Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2018-20947

Published Aug 1, 2019

cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10840

Published Aug 1, 2019

cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10365

Published Jul 31, 2019

Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by user…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11728

Published Jul 23, 2019

The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vul…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3970

Published Jul 17, 2019

Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Arbitrary File Write due to Cavwp.exe handling of Comodo's Antivirus database. Cavwp.exe loads Comodo antivirus defin…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-9186

Published Jul 3, 2019

In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-3569

Published Jun 26, 2019

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, whic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12929

Published Jun 24, 2019

The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achieve code execution, denial of service, or information discl…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12928

Published Jun 24, 2019

The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-1848

Published Jun 20, 2019

A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-12904

Published Jun 20, 2019

In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C impleme…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12875

Published Jun 18, 2019

Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted sign…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12274

Published Jun 6, 2019

In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher management plane because node driver options intentionally a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-4048

Published May 30, 2019

An exploitable local privilege elevation vulnerability exists in the file system permissions of the `Temp` directory in GOG Galaxy 1.2.48.36 (Windows 64-bit Installer). An attacke…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7846

Published May 22, 2019

A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium whi…

CVSS 9.8 · Critical

CVE-2018-20321

Published Apr 10, 2019

An issue was discovered in Rancher 2 through 2.1.5. Any project member with access to the default namespace can mount the netes-default service account in a pod, and then use that…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8934

Published Mar 21, 2019

hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/system-id and /proc/device-tree/model system attributes with a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-8308

Published Feb 12, 2019

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

CVSS 8.2 · High

CVE-2018-1840

Published Dec 3, 2018

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to gain elevated privileges on the system, caused when a security domain is configured to use a federate…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 651-675 of 727 CVEsPage 27 of 30