Skip to main content

CWE archive

CWE-281 CVEs

Programmatic archive

337 CVEs tagged with CWE-28131 Critical, 148 High, 132 Medium, 24 Low, 2 Unrated.

CVE-2020-13282

Published Aug 13, 2020

For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-8913

Published Aug 12, 2020

A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could creat…

CVSS 8.8 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2020-15113

Published Aug 5, 2020

In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed cert…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14958

Published Jun 21, 2020

In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20843

Published Jun 19, 2020

An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13763

Published Jun 2, 2020

In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2025

Published May 19, 2020

Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gai…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9781

Published Apr 1, 2020

The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10083

Published Mar 13, 2020

GitLab 12.7 through 12.8.1 has Insecure Permissions. Under certain conditions involving groups, project authorization changes were not being applied.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-8634

Published Mar 7, 2020

Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with wor…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9442

Published Feb 28, 2020

OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a m…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8633

Published Feb 18, 2020

An issue was discovered in Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7. When grantors revoked a shared calendar in Outlook, the calendar stayed mounted and accessible.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15621

Published Feb 4, 2020

Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13727

Published Dec 10, 2019

Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-19620

Published Dec 6, 2019

In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file. This is…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-18458

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of 4).

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-18457

Published Nov 26, 2019

An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13682

Published Nov 25, 2019

Insufficient policy enforcement in external protocol handling in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13668

Published Nov 25, 2019

Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16539

Published Nov 21, 2019

A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete support bundles.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 337 CVEsPage 12 of 14