Vulnerabilities (CVE)

Filtered by CWE-862
Total 2747 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-42671 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 5.5 MEDIUM
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42672 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 5.5 MEDIUM
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42673 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 5.5 MEDIUM
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42674 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 5.5 MEDIUM
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42675 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 5.5 MEDIUM
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42676 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 5.5 MEDIUM
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42677 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 5.5 MEDIUM
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42678 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 5.5 MEDIUM
In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-47870 1 Gvectors 1 Wpforo Forum 2023-12-06 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6.
CVE-2023-37890 1 Liquidweb 1 Kb Support 2023-12-06 N/A 4.3 MEDIUM
Missing Authorization vulnerability in WPOmnia KB Support – WordPress Help Desk and Knowledge Base allows Accessing Functionality Not Properly Constrained by ACLs. Users with a role as low as a subscriber can view other customers.This issue affects KB Support – WordPress Help Desk and Knowledge Base: from n/a through 1.5.88.
CVE-2023-49620 1 Apache 1 Dolphinscheduler 2023-12-05 N/A 6.5 MEDIUM
Before DolphinScheduler version 3.1.0, the login user could delete UDF function in the resource center unauthorized (which almost used in sql task), with unauthorized access vulnerability (IDOR), but after version 3.1.0 we fixed this issue. We mark this cve as moderate level because it still requires user login to operate, please upgrade to version 3.1.0 to avoid this vulnerability
CVE-2023-49652 1 Jenkins 1 Google Compute Engine 2023-12-05 N/A 2.7 LOW
Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins and to connect to Google Cloud Platform using attacker-specified credentials IDs obtained through another method, to obtain information about existing projects. This fix has been backported to 4.3.17.1.
CVE-2023-49674 1 Jenkins 1 Neuvector Vulnerability Scanner 2023-12-05 N/A 4.3 MEDIUM
A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.
CVE-2023-49654 1 Jenkins 1 Matlab 2023-12-05 N/A 9.8 CRITICAL
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.
CVE-2023-2448 1 Userproplugin 1 Userpro 2023-12-04 N/A 5.3 MEDIUM
The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'userpro_shortcode_template' function in versions up to, and including, 5.1.4. This makes it possible for unauthenticated attackers to arbitrary shortcode execution. An attacker can leverage CVE-2023-2446 to get sensitive information via shortcode.
CVE-2018-14628 2 Fedoraproject, Samba 2 Fedora, Samba 2023-12-04 N/A 4.3 MEDIUM
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
CVE-2023-5611 1 Seraphinitesolutions 1 Seraphinite Accelerator 2023-12-02 N/A 5.3 MEDIUM
The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them
CVE-2023-5737 1 Webtoffee 1 Backup And Migration 2023-12-01 N/A 4.3 MEDIUM
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.
CVE-2023-5525 1 Limitloginattempts 1 Limit Login Attempts Reloaded 2023-11-30 N/A 4.3 MEDIUM
The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.
CVE-2022-25190 1 Jenkins 1 Conjur Secrets 2023-11-30 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins Conjur Secrets Plugin 1.0.11 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.