Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,488 CVEs tagged with CWE-285126 Critical, 400 High, 665 Medium, 297 Low, 0 Unrated.

CVE-2023-32707

Published Jun 1, 2023

In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_u…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-34219

Published May 31, 2023

In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33189

Published May 30, 2023

Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33183

Published May 30, 2023

Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-2496

Published May 24, 2023

The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-28623

Published May 19, 2023

Zulip is an open-source team collaboration tool with unique topic-based threading. In the event that 1: `ZulipLDAPAuthBackend` and an external authentication backend (any aside of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2782

Published May 18, 2023

Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.3.1-38.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20184

Published May 18, 2023

Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user info…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20183

Published May 18, 2023

Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user info…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20182

Published May 18, 2023

Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user info…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22348

Published May 17, 2023

Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28325

Published May 11, 2023

An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28318

Published May 9, 2023

A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28317

Published May 9, 2023

A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2534

Published May 8, 2023

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into ove…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1,051-1,075 of 1,488 CVEsPage 43 of 60