Vulnerabilities (CVE)

Filtered by CWE-284
Total 2377 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-21813 2 Linux, Nvidia 9 Linux Kernel, Cloud Gaming Guest, Geforce and 6 more 2023-10-13 3.6 LOW 6.1 MEDIUM
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service.
CVE-2023-32632 1 Yifanwireless 2 Yf325, Yf325 Firmware 2023-10-12 N/A 9.8 CRITICAL
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.
CVE-2023-24479 1 Yifanwireless 2 Yf325, Yf325 Firmware 2023-10-12 N/A 9.8 CRITICAL
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.
CVE-2023-43696 1 Sick 2 Apu0200, Apu0200 Firmware 2023-10-11 N/A 9.8 CRITICAL
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
CVE-2023-36465 1 Decidim 1 Decidim 2023-10-11 N/A 7.1 HIGH
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys. This issue has been patched in version 0.26.8 and 0.27.4.
CVE-2023-43072 1 Dell 1 Smartfabric Storage Software 2023-10-06 N/A 7.8 HIGH
Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbritrary shell commands.
CVE-2023-0506 1 Bydemes 1 Airspace Cctv Web Service 2023-10-05 N/A 8.8 HIGH
The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain administrator access.
CVE-2023-5353 1 Salesagility 1 Suitecrm 2023-10-05 N/A 6.5 MEDIUM
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
CVE-2023-5106 1 Gitlab 1 Gitlab 2023-10-04 N/A 7.5 HIGH
An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.
CVE-2023-5207 1 Gitlab 1 Gitlab 2023-10-04 N/A 8.8 HIGH
A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.
CVE-2023-5198 1 Gitlab 1 Gitlab 2023-10-03 N/A 4.3 MEDIUM
An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.
CVE-2023-32477 1 Dell 1 Common Event Enabler 2023-10-03 N/A 7.8 HIGH
Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges.
CVE-2020-13677 1 Drupal 1 Drupal 2023-10-03 4.3 MEDIUM 7.5 HIGH
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.
CVE-2023-3115 1 Gitlab 1 Gitlab 2023-10-02 N/A 4.3 MEDIUM
An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.
CVE-2023-5288 1 Sick 2 Sim1012-0p0g200, Sim1012-0p0g200 Firmware 2023-10-02 N/A 9.8 CRITICAL
A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.
CVE-2023-32458 1 Emc 1 Appsync 2023-10-02 N/A 7.8 HIGH
Dell AppSync, versions 4.4.0.0 to 4.6.0.0 including Service Pack releases, contains an improper access control vulnerability in Embedded Service Enabler component. A local malicious user could potentially exploit this vulnerability during installation leading to a privilege escalation.
CVE-2023-41322 1 Glpi-project 1 Glpi 2023-09-29 N/A 8.8 HIGH
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A user with write access to another user can make requests to change the latter's password and then take control of their account. Users are advised to upgrade to version 10.0.10. There are no known work around for this vulnerability.
CVE-2020-25654 2 Clusterlabs, Debian 2 Pacemaker, Debian Linux 2023-09-29 9.0 HIGH 7.2 HIGH
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.
CVE-2023-39376 1 Siberiancms 1 Siberiancms 2023-09-27 N/A 6.5 MEDIUM
SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network
CVE-2020-10627 1 Insulet 2 Omnipod Insulin Management System, Omnipod Insulin Management System Firmware 2023-09-25 4.8 MEDIUM 8.1 HIGH
Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.