Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,675 CVEs tagged with CWE-862435 Critical, 1,954 High, 5,994 Medium, 291 Low, 1 Unrated.

CVE-2019-15576

Published Dec 18, 2019

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15013

Published Dec 18, 2019

The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16576

Published Dec 17, 2019

A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16574

Published Dec 17, 2019

A missing permission check in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16571

Published Dec 17, 2019

A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16567

Published Dec 17, 2019

A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentia…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16566

Published Dec 17, 2019

A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-sp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-2229

Published Dec 6, 2019

In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. This could lead to local information disclosure with no additi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-2218

Published Dec 6, 2019

In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing permission check. This could lead to local escalation of p…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-5865

Published Nov 25, 2019

Insufficient policy enforcement in navigations in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation v…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-13673

Published Nov 25, 2019

Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16547

Published Nov 21, 2019

Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attackers with Overall/Read permission to obtain limited informa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15387

Published Nov 14, 2019

The Archos Core 101 Android device with a build fingerprint of archos/MTKAC101CR3G_ARCHOS/ac101cr3g:7.0/NRD90M/20180611.034442:user/release-keys contains a pre-installed app with…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-0386

Published Nov 13, 2019

Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) do…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-6121

Published Nov 6, 2019

An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments,…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 8,351-8,375 of 8,675 CVEsPage 335 of 347