Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

9,181 CVEs tagged with CWE-862482 Critical, 2,118 High, 6,279 Medium, 301 Low, 1 Unrated.

CVE-2020-12745

Published May 11, 2020

An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can bypass the locked-state protection mechanism and access clipboard content via USSD. The Sams…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11671

Published May 4, 2020

Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10187

Published May 4, 2020

Doorkeeper version 5.0.0 and later contains an information disclosure vulnerability that allows an attacker to retrieve the client secret only intended for the OAuth application o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15877

Published Apr 28, 2020

In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in the ixl network driver failed to check whether the caller…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15876

Published Apr 28, 2020

In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driver specific ioctl command hand…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12138

Published Apr 27, 2020

AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the vir…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6212

Published Apr 24, 2020

Egypt localized withholding tax reports Clearing of Liabilities and Remittance Statement and Summary in SAP ERP (versions 618, 730, EAPPLGLO 607) and S/4 HANA (versions 100, 101,…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6823

Published Apr 24, 2020

A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and g…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-7278

Published Apr 15, 2020

Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6232

Published Apr 14, 2020

SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secur…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21047

Published Apr 8, 2020

An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Factory Reset Protection (FRP) bypass via the voice assistant because Internet access begins bef…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-21046

Published Apr 8, 2020

An issue was discovered on Samsung mobile devices with O(8.x) software. There is clipboard Data Exposure via the Emergency Dialer upon connecting a USB device. The Samsung ID is S…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-21042

Published Apr 8, 2020

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code e…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9514

Published Apr 7, 2020

An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress. wrappers.php allows a logged-in user (with the Subscriber role) to permanently delete arbi…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-11514

Published Apr 7, 2020

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke adm…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-18677

Published Apr 7, 2020

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. Because of an unprotected Intent, an attacker can reset the configuration of certain application…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18666

Published Apr 7, 2020

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Applications can send arbitrary premium SMS messages. The Samsung ID is SV…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-11036

Published Apr 7, 2020

An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10689

Published Apr 3, 2020

A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT pro…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11465

Published Apr 1, 2020

An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk appl…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11463

Published Apr 1, 2020

An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext cre…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 8,776-8,800 of 9,181 CVEsPage 352 of 368