Skip to content
Noroxi

CWE-671 · 6 records

Lack of Administrator Control over Security

CVEs in this class

6 records

  • Mjolnir v1.9.0 accepts commands from any room

    CriticalCVSS 9.1No exploitEPSS 1%

    matrix-org · mjolnirJan 21, 2025

  • Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2

    HighCVSS 8.3No exploitEPSS 0%

    nozomi networks · remote collectorJul 9, 2026

  • Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers

    HighCVSS 7.4No exploitEPSS 1%

    synology · ssl vpn clientApr 1, 2019

  • A vulnerability in the SFTP server implementation for Cisco Nexus 3000 Series Switches and 9000 Series Switches in standalone NX-OS mode cou

    MediumCVSS 5.4No exploitEPSS 1%

    cisco · nx-osAug 23, 2023

  • Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0

    MediumCVSS 5.3No exploitEPSS 0%

    nozomi networks · guardianSep 8, 2026

  • Bypass of password requirements when sharing a folder via the Circles app in Nextcloud Server

    MediumCVSS 4.3No exploitEPSS 1%

    nextcloud · nextcloud serverMay 20, 2022

All vulnerability classes