Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

734 CVEs tagged with CWE-66870 Critical, 242 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2020-13240

Published May 20, 2020

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12687

Published May 7, 2020

An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10867

Published Apr 1, 2020

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended acces…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10238

Published Mar 16, 2020

An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5159

Published Mar 11, 2020

An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware upd…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1981

Published Mar 11, 2020

A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute command…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10805

Published Feb 28, 2020

valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in fu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10790

Published Feb 17, 2020

taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7912

Published Jan 30, 2020

In JetBrains YouTrack before 2019.2.59309, SMTP/Jabber settings could be accessed using backups.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4633

Published Jan 28, 2020

IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 170007.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3682

Published Jan 17, 2020

The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort
Showing 601-625 of 734 CVEsPage 25 of 30