cwe-306
Safeguard articles tagged "cwe-306" — guides, analysis, and best practices for software supply chain and application security.
42 articles
CVE-2019-5591: Fortinet FortiOS Default Configuration Vulnerability
CVE-2019-5591 affects Fortinet FortiOS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-44077: Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
CVE-2021-44077 affects Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-12-01.
CVE-2021-37415: Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
CVE-2021-37415 affects Zoho ManageEngine ServiceDesk Plus (SDP) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-12-01.
CVE-2020-13927: Apache Airflow's Experimental API Authentication Bypass
CVE-2020-13927 affects Apache Airflow's Experimental API and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-01-18.
CVE-2020-3952: VMware vCenter Server Information Disclosure Vulnerability
CVE-2020-3952 affects VMware vCenter Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2019-9082: ThinkPHP Remote Code Execution Vulnerability
CVE-2019-9082 affects ThinkPHP ThinkPHP and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2021-20021: SonicWall Email Security Improper Privilege Management Vulnerability
CVE-2021-20021 affects SonicWall SonicWall Email Security and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2020-6207: SAP Solution Manager Missing Authentication for Critical Function Vulnerability
CVE-2020-6207 affects SAP Solution Manager and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2020-6287: SAP NetWeaver Missing Authentication for Critical Function Vulnerability
CVE-2020-6287 affects SAP NetWeaver and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2022-26143: MiCollab, MiVoice Business Express Access Control Vulnerability
CVE-2022-26143 affects Mitel MiCollab, MiVoice Business Express and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-25.
CVE-2022-1388: F5 BIG-IP Missing Authentication Vulnerability
CVE-2022-1388 affects F5 BIG-IP and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-05-10.
CVE-2022-26925: Microsoft Windows LSA Spoofing Vulnerability
CVE-2022-26925 affects Microsoft Windows and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-07-01.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.