Vulnerabilities (CVE)

Filtered by CWE-862
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-34344 1 Rymera 1 Wholesale Suite 2024-01-11 N/A 8.8 HIGH
Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More.This issue affects Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More: from n/a through 2.1.5.
CVE-2022-36352 1 Metagauss 1 Profilegrid 2024-01-11 N/A 8.8 HIGH
Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.0.3.
CVE-2023-6383 1 Bowo 1 Debug Log Manager 2024-01-11 N/A 7.5 HIGH
The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data
CVE-2023-42358 1 O-ran-sc 1 Ric-plt-e2mgr 2024-01-10 N/A 7.7 HIGH
An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service (DoS) via a crafted request to the E2Manager API component.
CVE-2023-4468 1 Poly 4 Lens, Trio 8800, Trio 8800 Firmware and 1 more 2024-01-09 N/A 7.6 HIGH
A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.
CVE-2023-22676 1 Andersthorborg 1 Advanced Custom Fields\ 2024-01-05 N/A 8.8 HIGH
Missing Authorization vulnerability in Anders Thorborg.This issue affects Anders Thorborg: from n/a through 1.4.12.
CVE-2023-49230 1 Peplink 2 Balance Two, Balance Two Firmware 2024-01-04 N/A 8.8 HIGH
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.
CVE-2023-51650 1 Dromara 1 Hertzbeat 2024-01-03 N/A 7.5 HIGH
Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this issue.
CVE-2023-22674 1 Halgatewood 1 Dashicons \+ Custom Post Types 2023-12-29 N/A 8.8 HIGH
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2.
CVE-2023-46212 1 Wpvnteam 1 Wp Extra 2023-12-22 N/A 8.8 HIGH
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects WP EXtra: from n/a through 6.2.
CVE-2023-48751 1 Xnau 1 Participants Database 2023-12-22 N/A 8.8 HIGH
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects Participants Database: from n/a through 2.5.5.
CVE-2021-39236 1 Apache 1 Ozone 2023-12-22 6.5 MEDIUM 8.8 HIGH
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
CVE-2021-39232 1 Apache 1 Ozone 2023-12-22 6.5 MEDIUM 8.8 HIGH
In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.
CVE-2023-40089 1 Google 1 Android 2023-12-22 N/A 7.8 HIGH
In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-40094 1 Google 1 Android 2023-12-22 N/A 7.8 HIGH
In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-5949 1 Wpmudev 1 Smartcrawl 2023-12-20 N/A 7.5 HIGH
The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content.
CVE-2023-48375 1 Csharp 1 Cws Collaborative Development Platform 2023-12-20 N/A 8.8 HIGH
SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.
CVE-2023-48676 2 Acronis, Microsoft 2 Cyber Protect Cloud Agent, Windows 2023-12-19 N/A 7.1 HIGH
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36943.
CVE-2023-47573 1 Relyum 4 Rely-pcie, Rely-pcie Firmware, Rely-rec and 1 more 2023-12-15 N/A 8.8 HIGH
An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged user to execute administrative functions.
CVE-2023-39167 1 Enbw 2 Senec Storage Box, Senec Storage Box Firmware 2023-12-14 N/A 7.5 HIGH
In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.
CVE-2023-48402 1 Google 1 Android 2023-12-12 N/A 7.8 HIGH
In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-44113 1 Huawei 2 Emui, Harmonyos 2023-12-11 N/A 7.5 HIGH
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-46354 1 Myprestamodules 1 Orders \(csv\, Excel\) Export Pro 2023-12-09 N/A 7.5 HIGH
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer/ps_address tables such as name / surname / email / phone number / full postal address.
CVE-2023-42748 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42747 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42746 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42745 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42743 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42740 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42739 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42738 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42736 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42696 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42681 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 7.8 HIGH
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2022-0492 6 Canonical, Debian, Fedoraproject and 3 more 30 Ubuntu Linux, Debian Linux, Fedora and 27 more 2023-12-07 6.9 MEDIUM 7.8 HIGH
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.
CVE-2023-42685 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42692 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42691 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42695 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42694 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42693 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42688 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42689 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42687 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42686 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42690 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-06 N/A 7.8 HIGH
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-6020 1 Ray Project 1 Ray 2023-12-06 N/A 7.5 HIGH
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023
CVE-2023-47870 1 Gvectors 1 Wpforo Forum 2023-12-06 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6.
CVE-2023-6038 1 H2o 1 H2o 2023-11-24 N/A 7.5 HIGH
An attacker is able to read any file on the server hosting the H2O dashboard without any authentication.
CVE-2023-39544 1 Nec 2 Expresscluster X, Expresscluster X Singleserversafe 2023-11-24 N/A 8.8 HIGH
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe 5.1 and earlier, EXPRESSCLUSTER X SingleServerSafe 5.1 and earlier allows a attacker to log in to the product may execute an arbitrary command.