Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,444 CVEs tagged with CWE-285123 Critical, 393 High, 643 Medium, 285 Low, 0 Unrated.

CVE-2023-22480

Published Jan 14, 2023

KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and b…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4701

Published Jan 10, 2023

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-10033

Published Jan 9, 2023

A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of the component Grade Handler. The manipulation leads to impr…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-4868

Published Dec 31, 2022

Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4804

Published Dec 28, 2022

Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4688

Published Dec 23, 2022

Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29913

Published Dec 22, 2022

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46312

Published Dec 20, 2022

The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23542

Published Dec 20, 2022

OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2536

Published Dec 15, 2022

The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47409

Published Dec 14, 2022

An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-39905

Published Dec 8, 2022

Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39890

Published Nov 9, 2022

Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39883

Published Nov 9, 2022

Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39879

Published Nov 9, 2022

Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39356

Published Nov 2, 2022

Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain a…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36454

Published Oct 25, 2022

A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper authorizati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36453

Published Oct 25, 2022

A vulnerability in the MiCollab Client API of Mitel MiCollab 9.1.3 through 9.5.0.101 could allow an authenticated attacker to modify their profile parameters due to improper autho…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,076-1,100 of 1,444 CVEsPage 44 of 58