Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,317 CVEs tagged with CWE-863317 Critical, 1,148 High, 1,600 Medium, 249 Low, 3 Unrated.

CVE-2020-5279

Published Apr 20, 2020

In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/cu…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6214

Published Apr 14, 2020

SAP S/4HANA (Financial Products Subledger), version 100, uses an incorrect authorization object in some reports. Although the affected reports are protected with other authorizati…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11707

Published Apr 12, 2020

An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-ad…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-21039

Published Apr 8, 2020

An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka QuickTools), an attacker can bypas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-21082

Published Apr 8, 2020

An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use screen lock type to unpin" option…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11628

Published Apr 8, 2020

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. It is intended to support restriction of available remote protocols (CMP, ACME, REST, etc.) through the sy…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8142

Published Apr 3, 2020

A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requ…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11802

Published Apr 1, 2020

In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5275

Published Mar 30, 2020

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDeci…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10510

Published Mar 27, 2020

Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a specific URL, access unauthori…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10239

Published Mar 16, 2020

An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5240

Published Mar 13, 2020

In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permission…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10534

Published Mar 12, 2020

In the GlobalBlocking extension before 2020-03-10 for MediaWiki through 1.34.0, an issue related to IP range evaluation resulted in blocked users re-gaining escalated privileges.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-0087

Published Mar 10, 2020

In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execut…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0036

Published Mar 10, 2020

In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions bypass. This could lead to local escalation of privilege wit…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13001

Published Mar 10, 2020

An issue was discovered in GitLab Community and Enterprise Edition 11.9 and later through 12.0.2. GitLab Snippets were vulnerable to an authorization issue that allowed unauthoriz…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2148

Published Mar 9, 2020

A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-spec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2135

Published Mar 9, 2020

Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2134

Published Mar 9, 2020

Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5251

Published Mar 4, 2020

In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9381

Published Feb 24, 2020

controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be exploited in conjunction with CVE-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 2,976-3,000 of 3,317 CVEsPage 120 of 133