Skip to content
Noroxi

CWE-264 · 5,366 records

Permissions, Privileges, and Access Controls

CVEs in this class

5,366 records

  • CVE-2013-6955
    65This week

    webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 al

    CriticalCVSS 10.0WeaponizedEPSS 85%

    synology · diskstation managerJan 9, 2014

  • CVE-2019-1620
    64This week

    Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability

    CriticalCVSS 9.8WeaponizedEPSS 84%

    cisco · data center network managerJun 26, 2019

  • CVE-2016-10372
    64This week

    The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port

    CriticalCVSS 9.8WeaponizedEPSS 82%

    eir · d1000 modem firmwareMay 16, 2017

  • CVE-2014-9583
    64This week

    common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and ot

    CriticalCVSS 10.0WeaponizedEPSS 80%

    asus · wrt firmwareJan 8, 2015

  • CVE-2009-3843
    64This week

    HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers

    CriticalCVSS 10.0WeaponizedEPSS 79%

    hp · operations managerNov 23, 2009

  • CVE-2015-7709
    64This week

    The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication

    CriticalCVSS 10.0WeaponizedEPSS 79%

    arkeia · western digital arkeiaOct 5, 2015

  • CVE-2014-7862
    63This week

    The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create ad

    CriticalCVSS 9.8WeaponizedEPSS 81%

    zohocorp · desktop centralJan 4, 2018

  • CVE-1999-1011
    63This week

    The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, wh

    CriticalCVSS 10.0WeaponizedEPSS 77%

    microsoft · data access componentsJul 19, 1999

  • CVE-2015-2794
    62This week

    The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via

    CriticalCVSS 9.8Proof of conceptEPSS 75%

    dnnsoftware · dotnetnukeFeb 6, 2017

  • CVE-2015-2284
    62This week

    userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbi

    CriticalCVSS 10.0WeaponizedEPSS 73%

    solarwinds · firewall security managerMar 24, 2015

  • CVE-2007-2815
    62This week

    The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL

    CriticalCVSS 10.0Proof of conceptEPSS 73%

    microsoft · internet information servicesMay 22, 2007

  • CVE-2012-0297
    62This week

    The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote

    CriticalCVSS 10.0WeaponizedEPSS 73%

    symantec · web gatewayMay 21, 2012

  • CVE-2016-3643
    62This week

    SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demons

    HighCVSS 7.8KEVWeaponizedEPSS 4%

    solarwinds · virtualization managerJun 17, 2016

  • CVE-2015-7766
    60This week

    PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions vi

    CriticalCVSS 9.0WeaponizedEPSS 81%

    zohocorp · manageengine opmanagerOct 9, 2015

  • CVE-2009-3068
    60This week

    Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to

    CriticalCVSS 9.3WeaponizedEPSS 78%

    adobe · robohelp serverSep 4, 2009

  • CVE-2016-1909
    60This week

    Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.

    CriticalCVSS 9.8WeaponizedEPSS 71%

    fortinet · fortiosJan 15, 2016

  • CVE-2011-5010
    60This week

    apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters i

    CriticalCVSS 10.0WeaponizedEPSS 66%

    ctekproducts · skyrouterDec 24, 2011

  • ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers

    HighCVSS 7.5WeaponizedEPSS 98%

    apache · strutsApr 29, 2014

  • Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in t

    CriticalCVSS 9.3WeaponizedEPSS 74%

    adobe · acrobat readerApr 5, 2010

  • The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to e

    CriticalCVSS 9.3WeaponizedEPSS 72%

    adobe · adobe readerApr 15, 2014

  • Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before

    CriticalCVSS 9.8Proof of conceptEPSS 68%

    oracle · mysqlSep 20, 2016

  • The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code

    CriticalCVSS 10.0WeaponizedEPSS 64%

    symantec · web gatewayMay 21, 2012

  • A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass au

    CriticalCVSS 9.8Proof of conceptEPSS 62%

    cisco · prime collaboration provisioningMay 18, 2017

  • web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst

    CriticalCVSS 10.0Proof of conceptEPSS 59%

    zte · f460Mar 11, 2014

  • The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,

    CriticalCVSS 9.0WeaponizedEPSS 69%

    f5 · big-iq securityDec 7, 2015

All vulnerability classes