Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2019-19015

Published Dec 2, 2019

An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connections to the internal PostgreSQL database of the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-16387

Published Nov 26, 2019

PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (T…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16541

Published Nov 21, 2019

Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System s…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0023

Published Nov 15, 2019

OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18954

Published Nov 14, 2019

Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/han…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4306

Published Oct 29, 2019

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the mo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13546

Published Oct 25, 2019

In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthorized attacker with physical acce…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12660

Published Sep 25, 2019

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15138

Published Sep 20, 2019

The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 626-650 of 727 CVEsPage 26 of 30