Skip to main content

CWE archive

CWE-281 CVEs

Programmatic archive

337 CVEs tagged with CWE-28131 Critical, 148 High, 132 Medium, 24 Low, 2 Unrated.

CVE-2021-21735

Published Jun 10, 2021

A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain som…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0074

Published Jun 9, 2021

Improper permissions in the installer for the Intel(R) Computing Improvement Program software before version 2.4.5982 may allow an authenticated user to potentially enable escalat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27383

Published Jun 9, 2021

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22137

Published May 13, 2021

In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve secu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30482

Published May 11, 2021

In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-18890

Published May 6, 2021

Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3418

Published Mar 15, 2021

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-21379

Published Mar 12, 2021

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform, the `{{wikimacrocontent}}` execute…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20263

Published Mar 9, 2021

A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on fi…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-23963

Published Feb 26, 2021

When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently gran…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26246

Published Dec 3, 2020

Pimcore is an open source digital experience platform. In Pimcore before version 6.8.5 it is possible to modify & create website settings without having the appropriate permission…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5796

Published Nov 13, 2020

Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users be…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12353

Published Nov 12, 2020

Improper permissions in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable denial of service via network access.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12345

Published Nov 12, 2020

Improper permissions in the installer for the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable escalation of privile…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12335

Published Nov 12, 2020

Improper permissions in the installer for the Intel(R) Processor Identification Utility before version 6.4.0603 may allow an authenticated user to potentially enable escalation of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12334

Published Nov 12, 2020

Improper permissions in the installer for the Intel(R) Advisor tools before version 2020 Update 2 may allow an authenticated user to potentially enable escalation of privilege via…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12332

Published Nov 12, 2020

Improper permissions in the installer for the Intel(R) HID Event Filter Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via loc…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8182

Published Oct 5, 2020

Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0405

Published Sep 18, 2020

In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13308

Published Sep 15, 2020

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by be…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort
Showing 251-275 of 337 CVEsPage 11 of 14