Auto-created placeholder
Volume of CVEs assigned to CWE-275 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
110 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-15379CRITICAL A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an | Oct 5, 2018 | 9.8 | 89 | NO | YES |
CVE-2017-16887CRITICAL The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can re | Jan 12, 2018 | 9.8 | 59 | NO | YES |
CVE-2014-1632HIGH htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter. | Jan 31, 2018 | 8.1 | 41 | NO | YES |
CVE-2014-1631HIGH Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php. | Jan 31, 2018 | 7.5 | 38 | NO | YES |
CVE-2017-17876HIGH Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter. | Dec 27, 2017 | 7.5 | 36 | NO | YES |
CVE-2014-6047MEDIUM phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks. | Aug 28, 2018 | 5.3 | 32 | NO | YES |
CVE-2017-6513CRITICAL The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual ma | Mar 11, 2017 | 9.9 | 32 | NO | NO |
CVE-2020-14496CRITICAL Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escal | May 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-22566CRITICAL An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged | Jan 18, 2022 | 9.8 | 30 | NO | NO |
CVE-2017-17060CRITICAL OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions. | May 23, 2019 | 9.8 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.