VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

462 CVEsRSS

CVE-2022-23383Critical· 9.1
4y ago

YzmCMS v6.3 is affected by broken access control

YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vuln…

▾ Midnightyzmcms · yzmcmsEPSS 1.2%via NVD
CVE-2022-23635High· 7.5
4y ago

Istio is an open platform to connect, manage, and secure microservices

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted mes…

▾ Twilightistio · istioEPSS 1.7%via NVD
CVE-2022-23320High· 7.5
4y ago

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries

XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensit…

▾ Twilightxerox · xmpie_ustoreEPSS 1.6%via NVD
CVE-2021-41716Critical· 9.8
4y ago

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

▾ Midnightmahadiscom · mahavitaranEPSS 1.3%via NVD
CVE-2021-29047High· 7.5
5y ago

The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCH…

The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCH…

▾ Twilightliferay · dxpEPSS 1.1%via NVD
CVE-2021-22893Critical· 10.0CISA KEVPoC
5y ago

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…

▾ Hadalivanti · connect_secureEPSS 47%via NVD
CVE-2021-27990High· 7.5
5y ago

Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.

Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.

▾ Twilightappspace · appspaceEPSS 1.4%via NVD
CVE-2020-28874High· 7.5PoC
5y ago

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic

reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).

▾ Midnightprojectsend · projectsendEPSS 2.4%via NVD
CVE-2020-3565Medium· 5.8
5y ago

A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices …

A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices …

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.94%via NVD
CVE-2020-12812Critical· 9.8CISA KEV
6y ago

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…

▾ Hadalfortinet · fortiosEPSS 49%via NVD
CVE-2019-1980Medium· 5.3
6y ago

A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to …

A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to …

▾ Sunlitcisco · firepower_services_software_for_asaEPSS 0.97%via NVD
CVE-2019-1946Medium· 6.5
7y ago

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management int…

A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-based management int…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 1.4%via NVD
CWE-287 vulnerabilities (CVEs) — page 16 · VulnSea