İçeriğe atla
Noroxi

CWE-264 · 5.366 kayıt

Permissions, Privileges, and Access Controls

Bu sınıftaki CVE’ler

5.366 kayıt

  • CVE-2013-6955
    65Bu hafta

    webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 al

    KritikCVSS 10,0SilahlaştırılmışEPSS %85

    synology · diskstation manager9 Oca 2014

  • CVE-2019-1620
    64Bu hafta

    Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability

    KritikCVSS 9,8SilahlaştırılmışEPSS %84

    cisco · data center network manager26 Haz 2019

  • CVE-2016-10372
    64Bu hafta

    The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port

    KritikCVSS 9,8SilahlaştırılmışEPSS %82

    eir · d1000 modem firmware16 May 2017

  • CVE-2014-9583
    64Bu hafta

    common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and ot

    KritikCVSS 10,0SilahlaştırılmışEPSS %80

    asus · wrt firmware8 Oca 2015

  • CVE-2009-3843
    64Bu hafta

    HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers

    KritikCVSS 10,0SilahlaştırılmışEPSS %79

    hp · operations manager23 Kas 2009

  • CVE-2015-7709
    64Bu hafta

    The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication

    KritikCVSS 10,0SilahlaştırılmışEPSS %79

    arkeia · western digital arkeia5 Eki 2015

  • CVE-2014-7862
    63Bu hafta

    The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create ad

    KritikCVSS 9,8SilahlaştırılmışEPSS %81

    zohocorp · desktop central4 Oca 2018

  • CVE-1999-1011
    63Bu hafta

    The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, wh

    KritikCVSS 10,0SilahlaştırılmışEPSS %77

    microsoft · data access components19 Tem 1999

  • CVE-2015-2794
    62Bu hafta

    The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via

    KritikCVSS 9,8Kavram kanıtıEPSS %75

    dnnsoftware · dotnetnuke6 Şub 2017

  • CVE-2015-2284
    62Bu hafta

    userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbi

    KritikCVSS 10,0SilahlaştırılmışEPSS %73

    solarwinds · firewall security manager24 Mar 2015

  • CVE-2007-2815
    62Bu hafta

    The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL

    KritikCVSS 10,0Kavram kanıtıEPSS %73

    microsoft · internet information services22 May 2007

  • CVE-2012-0297
    62Bu hafta

    The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote

    KritikCVSS 10,0SilahlaştırılmışEPSS %73

    symantec · web gateway21 May 2012

  • CVE-2016-3643
    62Bu hafta

    SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demons

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %4

    solarwinds · virtualization manager17 Haz 2016

  • CVE-2015-7766
    60Bu hafta

    PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions vi

    KritikCVSS 9,0SilahlaştırılmışEPSS %81

    zohocorp · manageengine opmanager9 Eki 2015

  • CVE-2009-3068
    60Bu hafta

    Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to

    KritikCVSS 9,3SilahlaştırılmışEPSS %78

    adobe · robohelp server4 Eyl 2009

  • CVE-2016-1909
    60Bu hafta

    Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.

    KritikCVSS 9,8SilahlaştırılmışEPSS %71

    fortinet · fortios15 Oca 2016

  • CVE-2011-5010
    60Bu hafta

    apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters i

    KritikCVSS 10,0SilahlaştırılmışEPSS %66

    ctekproducts · skyrouter24 Ara 2011

  • CVE-2014-0112
    59Planlayın

    ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers

    YüksekCVSS 7,5SilahlaştırılmışEPSS %98

    apache · struts29 Nis 2014

  • CVE-2010-1240
    59Planlayın

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in t

    KritikCVSS 9,3SilahlaştırılmışEPSS %74

    adobe · acrobat reader5 Nis 2010

  • CVE-2014-0514
    59Planlayın

    The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to e

    KritikCVSS 9,3SilahlaştırılmışEPSS %72

    adobe · adobe reader15 Nis 2014

  • CVE-2016-6662
    59Planlayın

    Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before

    KritikCVSS 9,8Kavram kanıtıEPSS %68

    oracle · mysql20 Eyl 2016

  • CVE-2012-0299
    59Planlayın

    The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code

    KritikCVSS 10,0SilahlaştırılmışEPSS %64

    symantec · web gateway21 May 2012

  • CVE-2017-6622
    58Planlayın

    A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass au

    KritikCVSS 9,8Kavram kanıtıEPSS %62

    cisco · prime collaboration provisioning18 May 2017

  • CVE-2014-2321
    58Planlayın

    web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst

    KritikCVSS 10,0Kavram kanıtıEPSS %59

    zte · f46011 Mar 2014

  • CVE-2015-3628
    57Planlayın

    The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,

    KritikCVSS 9,0SilahlaştırılmışEPSS %69

    f5 · big-iq security7 Ara 2015

Tüm zafiyet sınıfları