CWE-264 · 5,366 records
Permissions, Privileges, and Access Controls
CVEs in this class
5,366 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
65This week | CVE-2013-6955Weaponized | webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 alsynology · diskstation manager · CWE-264 | Critical10.0 | — | 84.6% | Jan 9, 2014 |
64This week | CVE-2019-1620Weaponized | Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerabilitycisco · data center network manager · CWE-264 | Critical9.8 | — | 83.8% | Jun 26, 2019 |
64This week | CVE-2016-10372Weaponized | The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP porteir · d1000 modem firmware · CWE-264 | Critical9.8 | — | 81.8% | May 16, 2017 |
64This week | CVE-2014-9583Weaponized | common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and otasus · wrt firmware · CWE-264 | Critical10.0 | — | 80.2% | Jan 8, 2015 |
64This week | CVE-2009-3843Weaponized | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackershp · operations manager · CWE-264 | Critical10.0 | — | 79.0% | Nov 23, 2009 |
64This week | CVE-2015-7709Weaponized | The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authenticationarkeia · western digital arkeia · CWE-264 | Critical10.0 | — | 79.0% | Oct 5, 2015 |
63This week | CVE-2014-7862Weaponized | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create adzohocorp · desktop central · CWE-264 | Critical9.8 | — | 81.0% | Jan 4, 2018 |
63This week | CVE-1999-1011Weaponized | The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, whmicrosoft · data access components · CWE-264 | Critical10.0 | — | 77.1% | Jul 19, 1999 |
62This week | CVE-2015-2794Proof of concept | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via dnnsoftware · dotnetnuke · CWE-264 | Critical9.8 | — | 75.1% | Feb 6, 2017 |
62This week | CVE-2015-2284Weaponized | userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbisolarwinds · firewall security manager · CWE-264 | Critical10.0 | — | 73.5% | Mar 24, 2015 |
62This week | CVE-2007-2815Proof of concept | The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACLmicrosoft · internet information services · CWE-264 | Critical10.0 | — | 73.4% | May 22, 2007 |
62This week | CVE-2012-0297Weaponized | The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote symantec · web gateway · CWE-264 | Critical10.0 | — | 73.0% | May 21, 2012 |
62This week | CVE-2016-3643Weaponized | SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonssolarwinds · virtualization manager · CWE-264 | High7.8 | KEV | 3.7% | Jun 17, 2016 |
60This week | CVE-2015-7766Weaponized | PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions vizohocorp · manageengine opmanager · CWE-264 | Critical9.0 | — | 80.6% | Oct 9, 2015 |
60This week | CVE-2009-3068Weaponized | Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers toadobe · robohelp server · CWE-264 | Critical9.3 | — | 78.2% | Sep 4, 2009 |
60This week | CVE-2016-1909Weaponized | Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.fortinet · fortios · CWE-264 | Critical9.8 | — | 71.3% | Jan 15, 2016 |
60This week | CVE-2011-5010Weaponized | apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters ictekproducts · skyrouter · CWE-264 | Critical10.0 | — | 65.7% | Dec 24, 2011 |
59Plan | CVE-2014-0112Weaponized | ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackersapache · struts · CWE-264 | High7.5 | — | 97.9% | Apr 29, 2014 |
59Plan | CVE-2010-1240Weaponized | Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in tadobe · acrobat reader · CWE-264 | Critical9.3 | — | 73.6% | Apr 5, 2010 |
59Plan | CVE-2014-0514Weaponized | The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to eadobe · adobe reader · CWE-264 | Critical9.3 | — | 72.2% | Apr 15, 2014 |
59Plan | CVE-2016-6662Proof of concept | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x beforeoracle · mysql · CWE-264 | Critical9.8 | — | 67.7% | Sep 20, 2016 |
59Plan | CVE-2012-0299Weaponized | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary codesymantec · web gateway · CWE-264 | Critical10.0 | — | 63.7% | May 21, 2012 |
58Plan | CVE-2017-6622Proof of concept | A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass aucisco · prime collaboration provisioning · CWE-264 | Critical9.8 | — | 62.2% | May 18, 2017 |
58Plan | CVE-2014-2321Proof of concept | web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstzte · f460 · CWE-264 | Critical10.0 | — | 59.3% | Mar 11, 2014 |
57Plan | CVE-2015-3628Weaponized | The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,f5 · big-iq security · CWE-264 | Critical9.0 | — | 69.3% | Dec 7, 2015 |
- CVE-2013-695565This week
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 al
CriticalCVSS 10.0WeaponizedEPSS 85%synology · diskstation managerJan 9, 2014
- CVE-2019-162064This week
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
CriticalCVSS 9.8WeaponizedEPSS 84%cisco · data center network managerJun 26, 2019
- CVE-2016-1037264This week
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port
CriticalCVSS 9.8WeaponizedEPSS 82%eir · d1000 modem firmwareMay 16, 2017
- CVE-2014-958364This week
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and ot
CriticalCVSS 10.0WeaponizedEPSS 80%asus · wrt firmwareJan 8, 2015
- CVE-2009-384364This week
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers
CriticalCVSS 10.0WeaponizedEPSS 79%hp · operations managerNov 23, 2009
- CVE-2015-770964This week
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication
CriticalCVSS 10.0WeaponizedEPSS 79%arkeia · western digital arkeiaOct 5, 2015
- CVE-2014-786263This week
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create ad
CriticalCVSS 9.8WeaponizedEPSS 81%zohocorp · desktop centralJan 4, 2018
- CVE-1999-101163This week
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, wh
CriticalCVSS 10.0WeaponizedEPSS 77%microsoft · data access componentsJul 19, 1999
- CVE-2015-279462This week
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via
CriticalCVSS 9.8Proof of conceptEPSS 75%dnnsoftware · dotnetnukeFeb 6, 2017
- CVE-2015-228462This week
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbi
CriticalCVSS 10.0WeaponizedEPSS 73%solarwinds · firewall security managerMar 24, 2015
- CVE-2007-281562This week
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL
CriticalCVSS 10.0Proof of conceptEPSS 73%microsoft · internet information servicesMay 22, 2007
- CVE-2012-029762This week
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote
CriticalCVSS 10.0WeaponizedEPSS 73%symantec · web gatewayMay 21, 2012
- CVE-2016-364362This week
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demons
HighCVSS 7.8KEVWeaponizedEPSS 4%solarwinds · virtualization managerJun 17, 2016
- CVE-2015-776660This week
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions vi
CriticalCVSS 9.0WeaponizedEPSS 81%zohocorp · manageengine opmanagerOct 9, 2015
- CVE-2009-306860This week
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to
CriticalCVSS 9.3WeaponizedEPSS 78%adobe · robohelp serverSep 4, 2009
- CVE-2016-190960This week
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.
CriticalCVSS 9.8WeaponizedEPSS 71%fortinet · fortiosJan 15, 2016
- CVE-2011-501060This week
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters i
CriticalCVSS 10.0WeaponizedEPSS 66%ctekproducts · skyrouterDec 24, 2011
- CVE-2014-011259Plan
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers
HighCVSS 7.5WeaponizedEPSS 98%apache · strutsApr 29, 2014
- CVE-2010-124059Plan
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in t
CriticalCVSS 9.3WeaponizedEPSS 74%adobe · acrobat readerApr 5, 2010
- CVE-2014-051459Plan
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to e
CriticalCVSS 9.3WeaponizedEPSS 72%adobe · adobe readerApr 15, 2014
- CVE-2016-666259Plan
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before
CriticalCVSS 9.8Proof of conceptEPSS 68%oracle · mysqlSep 20, 2016
- CVE-2012-029959Plan
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code
CriticalCVSS 10.0WeaponizedEPSS 64%symantec · web gatewayMay 21, 2012
- CVE-2017-662258Plan
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass au
CriticalCVSS 9.8Proof of conceptEPSS 62%cisco · prime collaboration provisioningMay 18, 2017
- CVE-2014-232158Plan
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst
CriticalCVSS 10.0Proof of conceptEPSS 59%zte · f460Mar 11, 2014
- CVE-2015-362857Plan
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,
CriticalCVSS 9.0WeaponizedEPSS 69%f5 · big-iq securityDec 7, 2015