Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,317 CVEs tagged with CWE-863317 Critical, 1,148 High, 1,600 Medium, 249 Low, 3 Unrated.

CVE-2020-3227

Published Jun 3, 2020

A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to exec…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-4026

Published Jun 3, 2020

The CustomAppsRestResource list resource in Atlassian Navigator Links before version 3.3.23, from version 4.0.0 before version 4.3.7, from version 5.0.0 before 5.0.1, and from ver…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11844

Published May 29, 2020

Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions 2018.05 to 2019.11. - ArcSight…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-1831

Published May 29, 2020

HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.195(SP31C00E74R3P8) have an improper authorization vulnerability. The digital balance function does not sufficiently r…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-12391

Published May 26, 2020

Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albe…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-20801

Published May 18, 2020

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the Web…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0097

Published May 14, 2020

In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead to local escalation of privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12876

Published May 14, 2020

Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12875

Published May 14, 2020

Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitive information or functionality…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1998

Published May 13, 2020

An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the userna…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7921

Published May 6, 2020

Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2188

Published May 6, 2020

A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credential…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5333

Published May 4, 2020

RSA Archer, versions prior to 6.7 P3 (6.7.0.3), contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially explo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12477

Published Apr 29, 2020

The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the get…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10786

Published Apr 21, 2020

A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11753

Published Apr 20, 2020

An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute sc…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5293

Published Apr 20, 2020

In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific prices. The problem is fixed in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5288

Published Apr 20, 2020

"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5287

Published Apr 20, 2020

In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,951-2,975 of 3,317 CVEsPage 119 of 133