Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

6,366 CVEs tagged with CWE-284803 Critical, 2,245 High, 2,748 Medium, 567 Low, 3 Unrated.

CVE-2024-27803

Published May 14, 2024

A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to share items from the l…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-27790

Published May 14, 2024

Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in File…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1230

Published May 14, 2024

The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or incorrect nonce validation…

CVSS 4.3 · Medium

CVE-2022-32507

Published May 14, 2024

An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-0025

Published May 7, 2024

In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29207

Published May 7, 2024

An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. Affected Products: UniFi Connect Applicati…

CVSS 7.5 · High

CVE-2024-29206

Published May 7, 2024

An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Pro…

CVSS 2.2 · Low

CVE-2023-6810

Published May 7, 2024

The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function in all ver…

CVSS 4.3 · Medium

CVE-2024-34068

Published May 3, 2024

Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access cont…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34404

Published May 3, 2024

A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, only the cloud administrator shou…

CVSS 6.8 · Medium

CVE-2024-33396

Published May 2, 2024

An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

CVSS 8.4 · High

CVE-2024-1678

Published May 2, 2024

The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via the REST API. This makes it p…

CVSS 5.3 · Medium

CVE-2024-31967

Published May 2, 2024

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an una…

CVSS 9.1 · Critical

CVE-2024-31964

Published May 2, 2024

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an una…

CVSS 7.5 · High

CVE-2024-33393

Published May 1, 2024

An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

CVSS 6.2 · Medium

CVE-2024-22830

Published May 1, 2024

Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control when handling system resources. This allows a local attacker…

CVSS 5.3 · Medium

CVE-2024-32973

Published May 1, 2024

Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. In affected versions an attacker with the ability to actively intercept network traffic would be able t…

CVSS 4.8 · Medium

CVE-2024-28978

Published May 1, 2024

Dell OpenManage Enterprise, versions 3.10 and 4.0, contains an Improper Access Control vulnerability. A high privileged remote attacker could potentially exploit this vulnerabilit…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3746

Published Apr 30, 2024

The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or overwrite files.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49473

Published Apr 30, 2024

Shenzhen JF6000 Cloud Media Collaboration Processing Platform firmware version V1.2.0 and software version V2.0.0 build 6245 is vulnerable to Incorrect Access Control.

CVSS 9.8 · Critical

CVE-2024-4225

Published Apr 30, 2024

Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnera…

CVSS 7.6 · High

CVE-2024-33260

Published Apr 26, 2024

Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at jerry-core/parser/js/js-parser-expr.c

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4198

Published Apr 26, 2024

Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort
Showing 3,776-3,800 of 6,366 CVEsPage 152 of 255