Skip to main content

CWE archive

CWE-264 CVEs

Programmatic archive

5,485 CVEs tagged with CWE-264526 Critical, 1,824 High, 2,661 Medium, 474 Low, 0 Unrated.

CVE-2022-38058

Published Sep 9, 2022

Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36793

Published Sep 9, 2022

Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33970

Published Jul 27, 2022

Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36375

Published Jul 25, 2022

Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordPress.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33969

Published Jul 25, 2022

Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34487

Published Jul 21, 2022

Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-33198

Published Jul 21, 2022

Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-33036

Published Jun 15, 2022

In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36528

Published Jun 7, 2022

A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken access control. The attack require…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1548

Published May 3, 2022

Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook members to escalate their membership privileges and perform a…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-29444

Published May 2, 2022

Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subscriber or higher user role to e…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0237

Published Mar 17, 2022

Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker can hijack the flow of execution due to an unquoted argume…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23731

Published Mar 11, 2022

V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23709

Published Mar 3, 2022

A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 5,485 CVEsPage 5 of 220