Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,704 CVEs tagged with CWE-732142 Critical, 839 High, 625 Medium, 96 Low, 2 Unrated.

CVE-2018-15869

Published Aug 25, 2018

An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS rec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15809

Published Aug 23, 2018

AccuPOS 2017.8 is installed with the insecure "Authenticated Users: Modify" permission for files within the installation path. This may allow local attackers to compromise the int…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000226

Published Aug 20, 2018

Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Incorrec…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000649

Published Aug 20, 2018

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write f…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15491

Published Aug 18, 2018

A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisti…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1551

Published Aug 6, 2018

IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-5490

Published Aug 3, 2018

Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authentic…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12467

Published Aug 1, 2018

Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a simila…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8637

Published Aug 1, 2018

A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when includ…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2590

Published Jul 27, 2018

A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authe…

CVSS 8.1 · High

CVE-2018-0392

Published Jul 18, 2018

A vulnerability in the CLI of Cisco Policy Suite could allow an authenticated, local attacker to access files owned by another user. The vulnerability is due to insufficient acces…

CVSS 5.5 · Medium

CVE-2018-1000211

Published Jul 13, 2018

Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000209

Published Jul 13, 2018

Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Windows platforms that can result in Unprivileged users may ex…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000207

Published Jul 13, 2018

MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1,451-1,475 of 1,704 CVEsPage 59 of 69