CWE-671 · 6 records
Lack of Administrator Control over Security
CVEs in this class
6 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2025-24024No exploit | Mjolnir v1.9.0 accepts commands from any roommatrix-org · mjolnir · CWE-671 | Critical9.1 | — | 0.6% | Jan 21, 2025 |
33Monitor | CVE-2026-31985No exploit | Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2nozomi networks · remote collector · CWE-671 | High8.3 | — | 0.2% | Jul 9, 2026 |
29Monitor | CVE-2018-13283No exploit | Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackerssynology · ssl vpn client · CWE-671 | High7.4 | — | 1.4% | Apr 1, 2019 |
21Monitor | CVE-2023-20115No exploit | A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode coucisco · nx-os · CWE-671 | Medium5.4 | — | 0.6% | Aug 23, 2023 |
21Monitor | CVE-2026-33389No exploit | Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0nozomi networks · guardian · CWE-671 | Medium5.3 | — | 0.2% | Sep 8, 2026 |
17Monitor | CVE-2022-29163No exploit | Bypass of password requirements when sharing a folder via the Circles app in Nextcloud Servernextcloud · nextcloud server · CWE-671 | Medium4.3 | — | 1.1% | May 20, 2022 |
- CVE-2025-2402436Monitor
Mjolnir v1.9.0 accepts commands from any room
CriticalCVSS 9.1No exploitEPSS 1%matrix-org · mjolnirJan 21, 2025
- CVE-2026-3198533Monitor
Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2
HighCVSS 8.3No exploitEPSS 0%nozomi networks · remote collectorJul 9, 2026
- CVE-2018-1328329Monitor
Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers
HighCVSS 7.4No exploitEPSS 1%synology · ssl vpn clientApr 1, 2019
- CVE-2023-2011521Monitor
A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode cou
MediumCVSS 5.4No exploitEPSS 1%cisco · nx-osAug 23, 2023
- CVE-2026-3338921Monitor
Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0
MediumCVSS 5.3No exploitEPSS 0%nozomi networks · guardianSep 8, 2026
- CVE-2022-2916317Monitor
Bypass of password requirements when sharing a folder via the Circles app in Nextcloud Server
MediumCVSS 4.3No exploitEPSS 1%nextcloud · nextcloud serverMay 20, 2022