Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,501 CVEs tagged with CWE-285128 Critical, 402 High, 666 Medium, 305 Low, 0 Unrated.

CVE-2023-32678

Published Aug 25, 2023

Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38508

Published Aug 24, 2023

Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39403

Published Aug 13, 2023

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39402

Published Aug 13, 2023

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39401

Published Aug 13, 2023

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39400

Published Aug 13, 2023

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39399

Published Aug 13, 2023

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39398

Published Aug 13, 2023

Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-4243

Published Aug 9, 2023

The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authoriz…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-3957

Published Jul 27, 2023

The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in vers…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-36826

Published Jul 25, 2023

Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bun…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23568

Published Jul 25, 2023

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Personal Data Fields. This issue affects Command Centre: vEL…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25074

Published Jul 25, 2023

Improper privilege validation in Command Centre Server allows authenticated unprivileged operators to modify and view Competencies. This issue affects Command Centre: vEL8.9…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22428

Published Jul 24, 2023

Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage. This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32482

Published Jul 20, 2023

Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An authenticated malicious user with privileged access can push policies to unauthoriz…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36611

Published Jul 3, 2023

The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requir…

CVSS 6.5 · Medium
Showing 1,026-1,050 of 1,501 CVEsPage 42 of 61