VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

CVE-2018-8724High· 7.8
5y ago

K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control

K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is: K7TSMngr.exe.

▾ Twilightk7computing · antivriusEPSS 0.27%via NVD
CVE-2018-8044High· 7.8
5y ago

K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control

K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The component is: K7Sentry.sys.

▾ Twilightk7computing · antivriusEPSS 0.31%via NVD
CVE-2020-3578Medium· 5.3
5y ago

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and ac…

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and ac…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 1.2%via NVD
CVE-2020-15664Medium· 6.5
5y ago

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user con…

▾ Sunlitmozilla · firefoxEPSS 1.4%via NVD
CVE-2020-11753High· 8.8
6y ago

An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0

An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.…

▾ Twilightsonatype · nexus_repository_managerEPSS 1.7%via NVD
CVE-2018-1258High· 8.8
8y ago

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security

Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should …

▾ Twilightpivotal_software · spring_securityEPSS 2.5%via NVD
CWE-863 vulnerabilities (CVEs) — page 30 · VulnSea