Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,580 CVEs tagged with CWE-306941 Critical, 982 High, 608 Medium, 49 Low, 0 Unrated.

CVE-2019-10046

Published May 31, 2019

An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, libraries, and license information.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12500

Published May 31, 2019

The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because Bluetooth Low Energy commands have no server-side authentica…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6808

Published May 22, 2019

A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code exe…

CVSS 9.8 · Critical

CVE-2019-10919

Published May 14, 2019

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access to port 10005/tcp could perform device reconfigurations and…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-9727

Published May 13, 2019

Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to retrieve the GUI password hashes of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10950

Published Apr 30, 2019

Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authenti…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2019-7727

Published Apr 23, 2019

In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allow…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10946

Published Apr 10, 2019

An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access checks, allowing calls from unauthenticated users.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3941

Published Apr 9, 2019

Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5514

Published Apr 1, 2019

VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessible through a web socket. An attacker may exploit this issue…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 2,426-2,450 of 2,580 CVEsPage 98 of 104