Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 28799 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-51074 1 Json-path 1 Jayway Jsonpath 2024-01-11 N/A 5.3 MEDIUM
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
CVE-2023-47140 1 Ibm 1 Cics Transaction Gateway 2024-01-11 N/A 8.1 HIGH
IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls. IBM X-Force ID: 270259.
CVE-2023-50082 1 Pbootcms 1 Pbootcms 2024-01-10 N/A 7.5 HIGH
Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.
CVE-2024-20802 1 Samsung 1 Dex 2024-01-10 N/A 5.5 MEDIUM
Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.
CVE-2024-20806 1 Samsung 1 Android 2024-01-10 N/A 5.5 MEDIUM
Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.
CVE-2024-20808 1 Samsung 1 Nearby Device Scanning 2024-01-10 N/A 5.5 MEDIUM
Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.
CVE-2024-20809 1 Samsung 1 Nearby Device Scanning 2024-01-10 N/A 5.5 MEDIUM
Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.
CVE-2023-7102 1 Barracuda 10 Email Security Gateway 300, Email Security Gateway 300 Firmware, Email Security Gateway 400 and 7 more 2024-01-09 N/A 9.8 CRITICAL
Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.
CVE-2023-47882 1 Kamivision 1 Yi Iot 2024-01-09 N/A 7.1 HIGH
The Kami Vision YI IoT com.yunyi.smartcamera application through 4.1.9_20231127 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.
CVE-2023-50341 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 7.5 HIGH
HCL DRYiCE MyXalytics is impacted by Improper Access Control (Obsolete web pages) vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information and/or exposing a vulnerable endpoint.
CVE-2023-50343 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 6.5 MEDIUM
HCL DRYiCE MyXalytics is impacted by an Improper Access Control (Controller APIs) vulnerability. Certain API endpoints are accessible to Customer Admin Users that can allow access to sensitive information about other users.
CVE-2023-50344 1 Hcltech 1 Dryice Myxalytics 2024-01-09 N/A 5.4 MEDIUM
HCL DRYiCE MyXalytics is impacted by improper access control (Unauthenticated File Download) vulnerability. An unauthenticated user can download certain files.
CVE-2019-19295 1 Siemens 2 Sinvr 3 Central Control Server, Sinvr 3 Video Server 2024-01-09 4.0 MEDIUM 4.3 MEDIUM
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) does not enforce logging of security-relevant activities in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An authenticated remote attacker could exploit this vulnerability to perform covert actions that are not visible in the application log.
CVE-2019-18342 1 Siemens 1 Control Center Server 2024-01-09 7.5 HIGH 9.9 CRITICAL
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) does not properly limit its capabilities to the specified purpose. In conjunction with CVE-2019-18341, an unauthenticated remote attacker with network access to the CCS server could exploit this vulnerability to read or delete arbitrary files, or access other resources on the same server.
CVE-2023-23752 1 Joomla 1 Joomla\! 2024-01-09 N/A 5.3 MEDIUM
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
CVE-2023-50333 1 Mattermost 1 Mattermost Server 2024-01-08 N/A 4.3 MEDIUM
Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.
CVE-2023-47858 1 Mattermost 1 Mattermost Server 2024-01-08 N/A 4.3 MEDIUM
Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.
CVE-2023-39909 1 Ericsson 1 Network Manager 2024-01-08 N/A 8.8 HIGH
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.
CVE-2023-50708 1 Yiiframework 1 Yii2-authclient 2024-01-08 N/A 9.8 CRITICAL
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 `state` and OpenID Connect `nonce` is vulnerable for a `timing attack` since it is compared via regular string comparison (instead of `Yii::$app->getSecurity()->compareString()`). Version 2.2.15 contains a patch for the issue. No known workarounds are available.
CVE-2023-31293 1 Sesami 1 Cash Point \& Transport Optimizer 2024-01-08 N/A 4.3 MEDIUM
An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled.