CWE-264
1,421 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 23 of 29
- CVE-2016-9972MEDIUMCVSS 5.9EG 5.92017-06-27
IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information usi…
- CVE-2016-9984HIGHCVSS 8.8EG 8.82017-06-13
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.
- CVE-2017-12214HIGHCVSS 8.8EG 8.82017-09-21
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges.…
- CVE-2017-12226HIGHCVSS 8.8EG 8.82017-09-29
A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco New Generation Wireless Controllers (NGWC)…
- CVE-2017-12230HIGHCVSS 8.8EG 8.82017-09-29
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission setting…
- CVE-2017-12239MEDIUMCVSS 6.8EG 6.82017-09-29
A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an affected device's …
- CVE-2017-12251CRITICALCVSS 9.9EG 9.92017-10-19
A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciously with the services or virtual machines (VMs) operating remotely on an affected CSP devi…
- CVE-2017-12261HIGHCVSS 7.8EG 7.82017-11-02
A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to…
- CVE-2017-12266MEDIUMCVSS 4.2EG 4.22017-10-05
A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local attacker to run an executable file with privileges equivalent to those of Cisco Meeting App. The vulnerability is due …
- CVE-2017-12268MEDIUMCVSS 6.5EG 6.52017-10-05
A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable multiple network adapters, aka a Dual-Homed Interface vulnerability. The vulnerability is…
- CVE-2017-12342MEDIUMCVSS 6.8EG 6.82017-11-30
A vulnerability in the Open Agent Container (OAC) feature of Cisco Nexus Series Switches could allow an unauthenticated, local attacker to read and send packets outside the scope of the OAC. The vulnerability is due to insufficient interna…
- CVE-2017-12351MEDIUMCVSS 5.7EG 5.72017-11-30
A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outside the scope of the guest shell container. An attacker would need valid administrator cred…
- CVE-2017-12363MEDIUMCVSS 5.3EG 5.32017-11-30
A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An atta…
- CVE-2017-18376HIGHCVSS 8.8EG 8.82019-06-02
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/Use…
- CVE-2017-18383HIGHCVSS 7.8EG 7.82019-08-02
cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
- CVE-2017-18399LOWCVSS 3.7EG 3.72019-08-02
cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).
- CVE-2017-18413HIGHCVSS 7.8EG 7.82019-08-02
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
- CVE-2017-18450MEDIUMCVSS 4.5EG 4.52019-08-02
cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
- CVE-2017-18451MEDIUMCVSS 5.3EG 5.32019-08-02
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
- CVE-2017-18455LOWCVSS 2.7EG 2.72019-08-02
In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).
- CVE-2017-18584HIGHCVSS 7.5EG 7.52019-08-22
The post-pay-counter plugin before 2.731 for WordPress has no permissions check for an update-settinga action.
- CVE-2017-3801HIGHCVSS 8.8EG 8.82017-02-15
A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary workflow items with just an end-user profile, a Privilege Escalation Vulnerability. The vulner…
- CVE-2017-3813HIGHCVSS 7.8EG 7.82017-02-09
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vul…
- CVE-2017-3819HIGHCVSS 8.8EG 8.82017-03-15
A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 Series, ASR 5700 Series devices, and Cisco Virtualized Packet Core could allow an authenticated, re…
- CVE-2017-3831CRITICALCVSS 9.8EG 9.82017-03-15
A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerabili…
- CVE-2017-3832HIGHCVSS 7.5EG 7.52017-04-06
A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to…
- CVE-2017-6620MEDIUMCVSS 5.8EG 5.82017-05-03
A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrec…
- CVE-2017-6622CRITICALCVSS 9.8EG 9.82017-05-18
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missin…
- CVE-2017-6623HIGHCVSS 7.8EG 7.82017-05-18
A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the CPS appliance could allow an authenticated, local attacker to escalate their privilege level to root. The vulnerabilit…
- CVE-2017-6624MEDIUMCVSS 5.3EG 5.32017-05-03
A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthorized phone calls. The vulnerability is due to a configuration restriction in the toll-fraud …
- CVE-2017-6635MEDIUMCVSS 6.5EG 6.52017-05-22
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the …
- CVE-2017-6637MEDIUMCVSS 6.5EG 6.52017-05-22
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the …
- CVE-2017-6638HIGHCVSS 7.8EG 7.82017-06-08
A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and run an executable file with privileges equivalent to the Microsoft Windows SYS…
- CVE-2017-6640CRITICALCVSS 9.8EG 9.82017-06-08
A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. Th…
- CVE-2017-6713CRITICALCVSS 9.8EG 9.82017-07-06
A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access to the affected system. The vulnerability is due to static, default credentials for the Ci…
- CVE-2017-7916MEDIUMCVSS 6.5EG 6.52017-08-07
A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict pr…
- CVE-2017-8228HIGHCVSS 8.8EG 8.82019-07-03
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the user to add a new camera to the user's account to ensure that…
- CVE-2017-8230HIGHCVSS 8.8EG 8.82019-07-03
On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of security analysis it was identified that a low privileged user who belongs to the "user" gro…
- CVE-2017-9711MEDIUMCVSS 6.7EG 6.72024-11-22
Certain unprivileged processes are able to perform IOCTL calls.
- CVE-2018-0089HIGHCVSS 7.5EG 7.52018-01-18
A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconn…
- CVE-2018-0092HIGHCVSS 7.1EG 7.12018-01-18
A vulnerability in the network-operator user role implementation for Cisco NX-OS System Software could allow an authenticated, local attacker to improperly delete valid user accounts. The network-operator role should not be able to delete …
- CVE-2018-0095HIGHCVSS 7.8EG 7.82018-01-18
A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain ro…
- CVE-2018-0096MEDIUMCVSS 5.9EG 5.92018-01-18
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to perform a privilege escalation in which one virtual domain user can view and modify anothe…
- CVE-2018-0130CRITICALCVSS 9.8EG 9.82018-02-22
A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative access to an affected system. The vulnerabil…
- CVE-2018-0152HIGHCVSS 8.8EG 8.82018-03-28
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability exists because the affected software does …
- CVE-2018-0169HIGHCVSS 7.8EG 7.82018-03-28
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the …
- CVE-2018-0176HIGHCVSS 7.8EG 7.82018-03-28
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the …
- CVE-2018-0183MEDIUMCVSS 6.7EG 6.72018-03-28
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. T…
- CVE-2018-0184MEDIUMCVSS 6.7EG 6.72018-03-28
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. T…
- CVE-2018-0213HIGHCVSS 8.8EG 8.82018-03-08
A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An att…
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →