Total
3971 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-7055 | 1 Phpgurukul | 1 Online Notes Sharing System | 2024-11-21 | 4.3 Medium |
A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /user/profile.php of the component Contact Information Handler. The manipulation of the argument mobilenumber leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-248742 is the identifier assigned to this vulnerability. | ||||
CVE-2023-6773 | 1 Codeastro | 1 Pos And Inventory Management System | 2024-11-21 | 4.3 Medium |
A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /accounts_con/register_account of the component User Creation Handler. The manipulation of the argument account_type with the input Admin leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247909 was assigned to this vulnerability. | ||||
CVE-2023-6761 | 1 Thecosy | 1 Icecms | 2024-11-21 | 4.3 Medium |
A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247889 was assigned to this vulnerability. | ||||
CVE-2023-6758 | 1 Thecosy | 1 Icecms | 2024-11-21 | 5.3 Medium |
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247886 is the identifier assigned to this vulnerability. | ||||
CVE-2023-6578 | 1 Softwareag | 1 Webmethods | 2024-11-21 | 7.3 High |
A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. It is possible to launch the attack remotely. To access a file like /assets/ a popup may request username and password. By just clicking CANCEL you will be redirected to the directory. If you visited /invoke/wm.server/connect, you'll be able to see details like internal IPs, ports, and versions. In some cases if access to /assets/ is refused, you may enter /assets/x as a wrong value, then come back to /assets/ which we will show the requested data. It appears that insufficient access control is depending on referrer header data. VDB-247158 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
CVE-2023-6202 | 1 Mattermost | 1 Mattermost | 2024-11-21 | 4.3 Medium |
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards. | ||||
CVE-2023-5976 | 1 Microweber | 1 Microweber | 2024-11-21 | 4.3 Medium |
Improper Access Control in GitHub repository microweber/microweber prior to 2.0. | ||||
CVE-2023-5833 | 1 Mintplexlabs | 1 Anythingllm | 2024-11-21 | 8.8 High |
Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. | ||||
CVE-2023-5549 | 2 Fedoraproject, Moodle | 3 Extra Packages For Enterprise Linux, Fedora, Moodle | 2024-11-21 | 3.3 Low |
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. | ||||
CVE-2023-5543 | 2 Fedoraproject, Moodle | 3 Extra Packages For Enterprise Linux, Fedora, Moodle | 2024-11-21 | 3.3 Low |
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting. | ||||
CVE-2023-5542 | 2 Fedoraproject, Moodle | 3 Extra Packages For Enterprise Linux, Fedora, Moodle | 2024-11-21 | 3.3 Low |
Students in "Only see own membership" groups could see other students in the group, which should be hidden. | ||||
CVE-2023-5365 | 1 Hp | 1 Life | 2024-11-21 | 9.8 Critical |
HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure. | ||||
CVE-2023-5353 | 1 Salesagility | 1 Suitecrm | 2024-11-21 | 6.5 Medium |
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1. | ||||
CVE-2023-5299 | 1 Fujielectric | 1 Tellus Lite V-simulator | 2024-11-21 | 7.3 High |
A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system. | ||||
CVE-2023-5240 | 1 Devolutions | 1 Devolutions Server | 2024-11-21 | 7.5 High |
Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request. | ||||
CVE-2023-52114 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity. | ||||
CVE-2023-52105 | 1 Huawei | 1 Harmonyos | 2024-11-21 | 7.5 High |
The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability. | ||||
CVE-2023-51786 | 2024-11-21 | 9.1 Critical | ||
An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control. | ||||
CVE-2023-51390 | 1 Aiven | 1 Journalpump | 2024-11-21 | 6.5 Medium |
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if any. The problem has been patched in journalpump 2.5.0. | ||||
CVE-2023-51070 | 1 Qstar | 1 Archive Storage Manager | 2024-11-21 | 7.5 High |
An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server. |