Skip to main content

CWE archive

CWE-425 CVEs

Programmatic archive

235 CVEs tagged with CWE-42534 Critical, 75 High, 115 Medium, 11 Low, 0 Unrated.

CVE-2019-16386

Published Nov 26, 2019

PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17503

Published Oct 11, 2019

An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contai…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11326

Published Sep 20, 2019

An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product is protected by a login. A guest is allowed to log…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1220

Published Sep 11, 2019

A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Fe…

CVSS 4.3 · Medium

CVE-2019-13030

Published Aug 14, 2019

eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to start or stop the Node.js process, resulting in the ability to…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14347

Published Aug 6, 2019

Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9884

Published Jul 25, 2019

eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-13981

Published Jul 19, 2019

In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configura…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9552

Published Mar 4, 2019

Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6551

Published Feb 28, 2019

Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, wh…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6669

Published Dec 20, 2018

A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18922

Published Dec 13, 2018

add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 176-200 of 235 CVEsPage 8 of 10