Vulnerabilities (CVE)

Filtered by CWE-1270
Total 8 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-54593 2026-07-30 N/A 8.1 HIGH
Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; because the Panel issues JWTs carrying those same claims for lower-privilege operations such as WebSocket authentication and file-download links, an authenticated subuser could reuse one of those tokens (for example a WebSocket token obtained with only the websocket.connect permission) by replaying it against /upload/file to write arbitrary files to the same server, despite never being granted the file.create permission. This issue is fixed in Panel version 1.12.3 and Wings version 1.12.2.
CVE-2026-15831 2026-07-30 N/A 4.3 MEDIUM
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation.
CVE-2026-49499 1 Dell 1 Powerprotect Data Manager 2026-07-29 N/A 8.8 HIGH
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2025-59698 1 Entrust 10 Nshield 5c, Nshield 5c Firmware, Nshield Connect Xc Base and 7 more 2026-06-17 N/A 6.8 MEDIUM
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate attacker to gain access to the EOL legacy bootloader.
CVE-2023-32188 2026-06-17 N/A N/A
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.
CVE-2023-30524 1 Jenkins 1 Report Portal 2026-06-17 N/A 4.3 MEDIUM
Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.
CVE-2023-2882 1 Cbot 2 Cbot Core, Cbot Panel 2026-06-17 N/A 9.8 CRITICAL
Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
CVE-2023-22644 1 Suse 1 Manager Server 2026-06-17 N/A 5.5 MEDIUM
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.