Skip to main content

CWE archive

CWE-425 CVEs

Programmatic archive

237 CVEs tagged with CWE-42534 Critical, 75 High, 117 Medium, 11 Low, 0 Unrated.

CVE-2021-30144

Published Apr 6, 2021

The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22180

Published Mar 26, 2021

An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3113

Published Jan 17, 2021

Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20484

Published Jan 5, 2021

An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser afte…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35391

Published Jan 1, 2021

Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/Rout…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-25012

Published Jan 1, 2021

The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13474

Published Dec 28, 2020

In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29656

Published Dec 9, 2020

An information disclosure vulnerability exists in RT-AC88U Download Master before 3.1.0.108. A direct access to /downloadmaster/dm_apply.cgi?action_mode=initial&download_type=Gene…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28937

Published Dec 3, 2020

OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24765

Published Oct 20, 2020

InterMind iMind Server through 3.13.65 allows remote unauthenticated attackers to read the self-diagnostic archive via a direct api/rs/monitoring/rs/api/system/dump-diagnostic-inf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26150

Published Sep 30, 2020

info.php in Logaritmo Aware CallManager 2012 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-2388

Published May 13, 2020

In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11561

Published Apr 7, 2020

In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000111

Published Mar 11, 2020

Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8439

Published Mar 7, 2020

Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit URI, as demonstrated by login=victim to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17646

Published Mar 5, 2020

An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17645

Published Mar 5, 2020

An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct request for include/configuration…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17644

Published Mar 4, 2020

An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct request for include/configuratio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 237 CVEsPage 7 of 10