Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,491 CVEs tagged with CWE-863339 Critical, 1,209 High, 1,676 Medium, 264 Low, 3 Unrated.

CVE-2017-16773

Published Jul 5, 2018

Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for director…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0337

Published Jun 21, 2018

A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected devi…

CVSS 7.8 · High

CVE-2018-8927

Published Jun 14, 2018

Improper authorization vulnerability in SYNO.Cal.Event in Calendar before 2.1.2-0511 allows remote authenticated users to create arbitrary events via the (1) cal_id or (2) origina…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15695

Published Jun 13, 2018

When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privileges is allowed to deploy code by invoking an internal Geod…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0338

Published Jun 7, 2018

A vulnerability in the role-based access-checking mechanisms of Cisco Unified Computing System (UCS) Software could allow an authenticated, local attacker to execute arbitrary com…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000197

Published Jun 5, 2018

An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to r…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11142

Published May 31, 2018

The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible only from localhost. This res…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000155

Published May 24, 2018

OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply mess…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-2611

Published May 8, 2018

Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup di…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10212

Published Apr 25, 2018

An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device v…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1700

Published Apr 24, 2018

IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle…

CVSS 6.5 · Medium

CVE-2017-2599

Published Apr 11, 2018

Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000152

Published Apr 5, 2018

An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delet…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1766

Published Mar 30, 2018

Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,376-3,400 of 3,491 CVEsPage 136 of 140