Vulnerabilities (CVE)

Filtered by CWE-862
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6798 1 Themeisle 1 Rss Aggregator By Feedzy 2024-01-12 N/A 5.4 MEDIUM
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with author-level access or above to change the plugin's settings including proxy settings, which are also exposed to authors.
CVE-2023-6733 1 Wp-members Project 1 Wp-members 2024-01-10 N/A 6.5 MEDIUM
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including user emails, password hashes, usernames, and more.
CVE-2023-7068 1 Webtoffee 1 Woocommerce Pdf Invoices\, Packing Slips\, Delivery Notes And Shipping Labels 2024-01-09 N/A 6.5 MEDIUM
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to export orders which can contain sensitive information.
CVE-2024-0201 1 Webcodingplace 1 Product Expiry For Woocommerce 2024-01-09 N/A 4.3 MEDIUM
The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
CVE-2023-4164 1 Google 2 Android, Pixel 2024-01-09 N/A 5.5 MEDIUM
There is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of health data with no additional execution privileges needed.
CVE-2022-34781 1 Jenkins 1 Xebialabs Xl Release 2024-01-09 4.0 MEDIUM 6.5 MEDIUM
Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2022-30957 1 Jenkins 1 Ssh 2024-01-09 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2023-3482 1 Mozilla 1 Firefox 2024-01-07 N/A 6.5 MEDIUM
When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects Firefox < 115.
CVE-2023-49229 1 Peplink 2 Balance Two, Balance Two Firmware 2024-01-04 N/A 4.3 MEDIUM
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.
CVE-2023-49003 1 Simplemobiletools 1 Simple Dialer 2024-01-04 N/A 5.3 MEDIUM
An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interaction with com.simplemobiletools.dialer.activities.DialerActivity.
CVE-2022-2389 1 Funnelkit 1 Funnelkit Automations 2024-01-04 N/A 4.3 MEDIUM
The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automations
CVE-2020-0989 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2023-12-31 2.1 LOW 5.5 MEDIUM
<p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and access files.</p> <p>The security update addresses the vulnerability by correcting the how Windows MDM Diagnostics handles files.</p>
CVE-2023-5056 1 Redhat 2 Enterprise Linux, Service Interconnect 2023-12-29 N/A 4.1 MEDIUM
A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of information outside of the user's purview.
CVE-2023-25715 1 Gamipress 1 Gamipress 2023-12-28 N/A 6.5 MEDIUM
Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress.This issue affects GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress: from n/a through 2.5.6.
CVE-2022-27209 1 Jenkins 1 Kubernetes Continuous Deploy 2023-12-22 4.0 MEDIUM 6.5 MEDIUM
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2022-27215 1 Jenkins 1 Release Helper 2023-12-22 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
CVE-2022-29051 1 Jenkins 1 Publish Over Ftp 2023-12-22 4.0 MEDIUM 4.3 MEDIUM
Missing permission checks in Jenkins Publish Over FTP Plugin 1.16 and earlier allow attackers with Overall/Read permission to connect to an FTP server using attacker-specified credentials.
CVE-2022-28134 1 Jenkins 1 Bitbucket Server Integration 2023-12-22 5.5 MEDIUM 5.4 MEDIUM
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers.
CVE-2022-28137 1 Jenkins 1 Jiratestresultreporter 2023-12-22 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
CVE-2023-50779 1 Jenkins 1 Paaslane Estimate 2023-12-18 N/A 4.3 MEDIUM
Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.
CVE-2023-50765 1 Jenkins 1 Scriptler 2023-12-18 N/A 4.3 MEDIUM
A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read permission to read the contents of a Groovy script by knowing its ID.
CVE-2023-50767 1 Jenkins 1 Nexus Platform 2023-12-18 N/A 5.4 MEDIUM
Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.
CVE-2023-50769 1 Jenkins 1 Nexus Platform 2023-12-18 N/A 4.3 MEDIUM
Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2023-5711 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information provided by PHP info.
CVE-2023-5710 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information such as database credentials.
CVE-2023-5712 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive global value information.
CVE-2023-5713 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve potentially sensitive option values, and deserialize the content of those values.
CVE-2023-5714 1 Bowo 1 System Dashboard 2023-12-11 N/A 4.3 MEDIUM
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve data key specs.
CVE-2023-42749 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42744 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-42710 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42742 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-42741 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42737 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42735 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 4.4 MEDIUM
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
CVE-2023-42734 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42733 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42732 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42730 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-32855 5 Google, Linuxfoundation, Mediatek and 2 more 36 Android, Yocto, Mt2735 and 33 more 2023-12-07 N/A 6.7 MEDIUM
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.
CVE-2023-42711 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42713 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42712 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42714 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42706 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42707 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42708 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42709 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42702 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42703 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2023-12-07 N/A 5.5 MEDIUM
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed