Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

9,119 CVEs tagged with CWE-862479 Critical, 2,091 High, 6,248 Medium, 300 Low, 1 Unrated.

CVE-2021-41238

Published Nov 2, 2021

Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows Service or separate process required. Dashboard UI in Hangfi…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25019

Published Nov 1, 2021

The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, whic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39225

Published Oct 25, 2021

Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to ac…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24779

Published Oct 25, 2021

The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0706

Published Oct 22, 2021

In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missing permission check. This could lead to local denial of serv…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0643

Published Oct 22, 2021

In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due to a missing permission check.…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24677

Published Oct 18, 2021

The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37738

Published Oct 15, 2021

A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38431

Published Oct 15, 2021

An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20834

Published Oct 13, 2021

Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 and Nike App for iOS versions prior to 2.177.1 allows a remot…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39184

Published Oct 12, 2021

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40884

Published Oct 11, 2021

Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32172

Published Oct 7, 2021

Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-0686

Published Oct 6, 2021

In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user due to a missing permission che…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0682

Published Oct 6, 2021

In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. This could lead to local infor…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0681

Published Oct 6, 2021

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution pr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0680

Published Oct 6, 2021

In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution pr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39226

Published Oct 5, 2021

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by a…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
50.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-41554

Published Oct 5, 2021

ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endpoints: /archibus/schema/ab-edi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 8,326-8,350 of 9,119 CVEsPage 334 of 365