Перейти к содержимому
Noroxi

CWE-264 · 5 366 записей

Permissions, Privileges, and Access Controls

CVE этого класса

5 366 записей

  • CVE-2013-6955
    65На этой неделе

    webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 al

    КритическаяCVSS 10,0Готовый эксплойтEPSS 85 %

    synology · diskstation manager9 янв. 2014 г.

  • CVE-2019-1620
    64На этой неделе

    Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability

    КритическаяCVSS 9,8Готовый эксплойтEPSS 84 %

    cisco · data center network manager26 июн. 2019 г.

  • CVE-2016-10372
    64На этой неделе

    The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port

    КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %

    eir · d1000 modem firmware16 мая 2017 г.

  • CVE-2014-9583
    64На этой неделе

    common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and ot

    КритическаяCVSS 10,0Готовый эксплойтEPSS 80 %

    asus · wrt firmware8 янв. 2015 г.

  • CVE-2009-3843
    64На этой неделе

    HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers

    КритическаяCVSS 10,0Готовый эксплойтEPSS 79 %

    hp · operations manager23 нояб. 2009 г.

  • CVE-2015-7709
    64На этой неделе

    The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication

    КритическаяCVSS 10,0Готовый эксплойтEPSS 79 %

    arkeia · western digital arkeia5 окт. 2015 г.

  • CVE-2014-7862
    63На этой неделе

    The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create ad

    КритическаяCVSS 9,8Готовый эксплойтEPSS 81 %

    zohocorp · desktop central4 янв. 2018 г.

  • CVE-1999-1011
    63На этой неделе

    The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, wh

    КритическаяCVSS 10,0Готовый эксплойтEPSS 77 %

    microsoft · data access components19 июл. 1999 г.

  • CVE-2015-2794
    62На этой неделе

    The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via

    КритическаяCVSS 9,8Proof of conceptEPSS 75 %

    dnnsoftware · dotnetnuke6 февр. 2017 г.

  • CVE-2015-2284
    62На этой неделе

    userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbi

    КритическаяCVSS 10,0Готовый эксплойтEPSS 73 %

    solarwinds · firewall security manager24 мар. 2015 г.

  • CVE-2007-2815
    62На этой неделе

    The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL

    КритическаяCVSS 10,0Proof of conceptEPSS 73 %

    microsoft · internet information services22 мая 2007 г.

  • CVE-2012-0297
    62На этой неделе

    The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote

    КритическаяCVSS 10,0Готовый эксплойтEPSS 73 %

    symantec · web gateway21 мая 2012 г.

  • CVE-2016-3643
    62На этой неделе

    SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demons

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 4 %

    solarwinds · virtualization manager17 июн. 2016 г.

  • CVE-2015-7766
    60На этой неделе

    PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions vi

    КритическаяCVSS 9,0Готовый эксплойтEPSS 81 %

    zohocorp · manageengine opmanager9 окт. 2015 г.

  • CVE-2009-3068
    60На этой неделе

    Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to

    КритическаяCVSS 9,3Готовый эксплойтEPSS 78 %

    adobe · robohelp server4 сент. 2009 г.

  • CVE-2016-1909
    60На этой неделе

    Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 71 %

    fortinet · fortios15 янв. 2016 г.

  • CVE-2011-5010
    60На этой неделе

    apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters i

    КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %

    ctekproducts · skyrouter24 дек. 2011 г.

  • CVE-2014-0112
    59В плане

    ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 98 %

    apache · struts29 апр. 2014 г.

  • CVE-2010-1240
    59В плане

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in t

    КритическаяCVSS 9,3Готовый эксплойтEPSS 74 %

    adobe · acrobat reader5 апр. 2010 г.

  • CVE-2014-0514
    59В плане

    The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to e

    КритическаяCVSS 9,3Готовый эксплойтEPSS 72 %

    adobe · adobe reader15 апр. 2014 г.

  • CVE-2016-6662
    59В плане

    Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before

    КритическаяCVSS 9,8Proof of conceptEPSS 68 %

    oracle · mysql20 сент. 2016 г.

  • CVE-2012-0299
    59В плане

    The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code

    КритическаяCVSS 10,0Готовый эксплойтEPSS 64 %

    symantec · web gateway21 мая 2012 г.

  • CVE-2017-6622
    58В плане

    A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass au

    КритическаяCVSS 9,8Proof of conceptEPSS 62 %

    cisco · prime collaboration provisioning18 мая 2017 г.

  • CVE-2014-2321
    58В плане

    web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst

    КритическаяCVSS 10,0Proof of conceptEPSS 59 %

    zte · f46011 мар. 2014 г.

  • CVE-2015-3628
    57В плане

    The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,

    КритическаяCVSS 9,0Готовый эксплойтEPSS 69 %

    f5 · big-iq security7 дек. 2015 г.

Все классы уязвимостей