Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,675 CVEs tagged with CWE-862435 Critical, 1,954 High, 5,994 Medium, 291 Low, 1 Unrated.

CVE-2018-4059

Published Mar 21, 2019

An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticate…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17491

Published Mar 21, 2019

EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this v…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-17490

Published Mar 21, 2019

EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-9742

Published Mar 13, 2019

gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Characteristics lacks FILE_DEVICE_SECURE_OPEN and therefore fil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0270

Published Mar 12, 2019

ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has been corre…

CVSS 8.8 · High

CVE-2019-9713

Published Mar 12, 2019

An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1003037

Published Mar 8, 2019

An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attacke…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003036

Published Mar 8, 2019

A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003035

Published Mar 8, 2019

An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgentTemplate.java, src/main/j…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9574

Published Mar 5, 2019

The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in the context of the Administrator or HR Manager role.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9482

Published Mar 1, 2019

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The is…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003025

Published Feb 20, 2019

A exposure of sensitive information vulnerability exists in Jenkins Cloud Foundry Plugin 2.3.1 and earlier in AbstractCloudFoundryPushDescriptor.java that allows attackers with Ov…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0258

Published Feb 15, 2019

SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1003006

Published Feb 6, 2019

A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Re…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18996

Published Feb 5, 2019

LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the ser…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-1000017

Published Feb 4, 2019

Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all ticket…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6923

Published Jan 22, 2019

In Drupal 8.x prior to 8.3.7 When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict acce…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-5886

Published Jan 10, 2019

An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to rein…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 8,526-8,550 of 8,675 CVEsPage 342 of 347