CWE-671 · 6 записей
Lack of Administrator Control over Security
CVE этого класса
6 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2025-24024Эксплойта нет | Mjolnir v1.9.0 accepts commands from any roommatrix-org · mjolnir · CWE-671 | Критическая9,1 | — | 0,6 % | 21 янв. 2025 г. |
33Наблюдать | CVE-2026-31985Эксплойта нет | Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2nozomi networks · remote collector · CWE-671 | Высокая8,3 | — | 0,2 % | 9 июл. 2026 г. |
29Наблюдать | CVE-2018-13283Эксплойта нет | Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackerssynology · ssl vpn client · CWE-671 | Высокая7,4 | — | 1,4 % | 1 апр. 2019 г. |
21Наблюдать | CVE-2023-20115Эксплойта нет | A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode coucisco · nx-os · CWE-671 | Средняя5,4 | — | 0,6 % | 23 авг. 2023 г. |
21Наблюдать | CVE-2026-33389Эксплойта нет | Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0nozomi networks · guardian · CWE-671 | Средняя5,3 | — | 0,2 % | 8 сент. 2026 г. |
17Наблюдать | CVE-2022-29163Эксплойта нет | Bypass of password requirements when sharing a folder via the Circles app in Nextcloud Servernextcloud · nextcloud server · CWE-671 | Средняя4,3 | — | 1,1 % | 20 мая 2022 г. |
- CVE-2025-2402436Наблюдать
Mjolnir v1.9.0 accepts commands from any room
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %matrix-org · mjolnir21 янв. 2025 г.
- CVE-2026-3198533Наблюдать
Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %nozomi networks · remote collector9 июл. 2026 г.
- CVE-2018-1328329Наблюдать
Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %synology · ssl vpn client1 апр. 2019 г.
- CVE-2023-2011521Наблюдать
A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode cou
СредняяCVSS 5,4Эксплойта нетEPSS 1 %cisco · nx-os23 авг. 2023 г.
- CVE-2026-3338921Наблюдать
Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0
СредняяCVSS 5,3Эксплойта нетEPSS 0 %nozomi networks · guardian8 сент. 2026 г.
- CVE-2022-2916317Наблюдать
Bypass of password requirements when sharing a folder via the Circles app in Nextcloud Server
СредняяCVSS 4,3Эксплойта нетEPSS 1 %nextcloud · nextcloud server20 мая 2022 г.