Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,444 CVEs tagged with CWE-285123 Critical, 393 High, 643 Medium, 285 Low, 0 Unrated.

CVE-2022-39342

Published Oct 25, 2022

OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users whose model has a relation de…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39341

Published Oct 25, 2022

OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass under certain conditions. Users who have wildcard (`*`) defin…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39340

Published Oct 25, 2022

OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not validating the authorization header, resulting in disclosure of…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39322

Published Oct 25, 2022

@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-42961

Published Oct 15, 2022

An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34434

Published Oct 11, 2022

Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control vulnerability within the Postgres database. A threat actor with root level access to…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39873

Published Oct 7, 2022

Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32170

Published Sep 28, 2022

The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized user can view the “projects“ created by “Admin” and the affect…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32169

Published Sep 28, 2022

The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user can view the “OPEN” and “CLOSED” issues by “Admin” and the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36110

Published Sep 9, 2022

Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged users running privileged API calls. If someone adds users…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36876

Published Sep 9, 2022

Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-36852

Published Sep 9, 2022

Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-36848

Published Sep 9, 2022

Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36090

Published Sep 8, 2022

XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14.3-rc-1, some resources are missing a check for inactive (n…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31167

Published Sep 7, 2022

XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31247

Published Sep 7, 2022

An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-20921

Published Aug 25, 2022

A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. Thi…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1,101-1,125 of 1,444 CVEsPage 45 of 58