Skip to main content

CWE archive

CWE-425 CVEs

Programmatic archive

235 CVEs tagged with CWE-42534 Critical, 75 High, 115 Medium, 11 Low, 0 Unrated.

CVE-2022-28365

Published Apr 9, 2022

Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26279

Published Mar 24, 2022

EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24385

Published Mar 14, 2022

A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26159

Published Feb 28, 2022

The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24046

Published Jan 14, 2022

A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affecte…

CVSS 5.3 · Medium

CVE-2021-24831

Published Jan 3, 2022

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24695

Published Nov 8, 2021

The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthent…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36745

Published Sep 29, 2021

A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Wi…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-40875

Published Sep 22, 2021

Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20114

Published Jul 30, 2021

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28150

Published May 6, 2021

Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backup2.cgi.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-24215

Published Apr 12, 2021

An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionalit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-30144

Published Apr 6, 2021

The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22180

Published Mar 26, 2021

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 235 CVEsPage 6 of 10