cwe-863
Safeguard articles tagged "cwe-863" — guides, analysis, and best practices for software supply chain and application security.
17 articles
CVE-2021-22986: F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability
CVE-2021-22986 affects F5 BIG-IP and BIG-IQ Centralized Management and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2021-11-03.
CVE-2019-7192: QNAP Photo Station Improper Access Control Vulnerability
CVE-2019-7192 affects QNAP Photo Station and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-06-08.
CVE-2021-30533: Google Chromium PopupBlocker Security Bypass Vulnerability
CVE-2021-30533 affects Google Chromium PopupBlocker and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-06-27.
CVE-2022-41091: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
CVE-2022-41091 affects Microsoft Windows and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-11-08.
CVE-2023-21715: Microsoft Office Publisher Security Feature Bypass Vulnerability
CVE-2023-21715 affects Microsoft Office and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-02-14.
CVE-2023-24880: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
CVE-2023-24880 affects Microsoft Windows and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-03-14.
CVE-2021-3560: Red Hat Polkit Incorrect Authorization Vulnerability
CVE-2021-3560 affects Red Hat Polkit and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-05-12.
CVE-2023-38035: Ivanti Sentry Authentication Bypass Vulnerability
CVE-2023-38035 affects Ivanti Sentry and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-08-22.
CVE-2023-22518: Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
CVE-2023-22518 affects Atlassian Confluence Data Center and Server and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-11-07.
CVE-2021-40655: D-Link DIR-605 Router Information Disclosure Vulnerability
CVE-2021-40655 affects D-Link DIR-605 Router and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-05-16.
CVE-2024-38856: Apache OFBiz Incorrect Authorization Vulnerability
CVE-2024-38856 affects Apache OFBiz and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-08-27.
CVE-2024-21287: Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability
CVE-2024-21287 affects Oracle Agile Product Lifecycle Management (PLM) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-11-21.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.