Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

9,112 CVEs tagged with CWE-862478 Critical, 2,090 High, 6,242 Medium, 300 Low, 2 Unrated.

CVE-2020-0085

Published Mar 10, 2020

In setBluetoothTethering of PanService.java, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege to activate…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0084

Published Mar 10, 2020

In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local escalation of privilege by creating fake system notification…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0054

Published Mar 10, 2020

In WifiNetworkSuggestionsManager of WifiNetworkSuggestionsManager.java, there is a possible permission revocation due to a missing permission check. This could lead to local escal…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0047

Published Mar 10, 2020

In setMasterMute of AudioService.java, there is a missing permission check. This could lead to local silencing of audio with no additional execution privileges needed. User intera…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-0035

Published Mar 10, 2020

In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This could lead to local information disclosure with no addition…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2142

Published Mar 9, 2020

A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to trigger builds.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9458

Published Mar 6, 2020

In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and se…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-9457

Published Mar 6, 2020

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings v…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-9456

Published Mar 6, 2020

In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to admin…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-9455

Published Mar 6, 2020

The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-19989

Published Feb 26, 2020

An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0055

Published Feb 19, 2020

OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restricti…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6614

Published Feb 19, 2020

D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user passw…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-4226

Published Feb 18, 2020

The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0023

Published Feb 13, 2020

In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6188

Published Feb 12, 2020

VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 1…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-6183

Published Feb 12, 2020

SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive respo…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-8811

Published Feb 7, 2020

ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8772

Published Feb 6, 2020

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7993

Published Feb 3, 2020

Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8495

Published Jan 30, 2020

In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor priv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5228

Published Jan 30, 2020

Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 8,751-8,775 of 9,112 CVEsPage 351 of 365