Vulnerabilities (CVE)

Filtered by CWE-1220
Total 88 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40070 2 Apple, Intel 2 Macos, Power Gadget 2026-06-17 N/A 8.8 HIGH
Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2023-3227 1 Fossbilling 1 Fossbilling 2026-06-17 N/A 5.7 MEDIUM
Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.
CVE-2023-39418 3 Debian, Postgresql, Redhat 3 Debian Linux, Postgresql, Enterprise Linux 2026-06-17 N/A 3.1 LOW
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.
CVE-2023-33127 1 Microsoft 2 .net, Visual Studio 2022 2026-06-17 N/A 8.1 HIGH
.NET and Visual Studio Elevation of Privilege Vulnerability
CVE-2023-31343 2026-06-17 N/A 7.5 HIGH
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
CVE-2023-31342 2026-06-17 N/A 7.5 HIGH
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
CVE-2022-4813 1 Usememos 1 Memos 2026-06-17 N/A 4.3 MEDIUM
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4801 1 Usememos 1 Memos 2026-06-17 N/A 5.3 MEDIUM
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.