Vulnerabilities (CVE)

Filtered by CWE-285
Total 1060 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-39400 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 9.1 CRITICAL
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
CVE-2023-39399 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 9.1 CRITICAL
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
CVE-2023-39398 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 9.1 CRITICAL
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
CVE-2023-38220 1 Adobe 2 Commerce, Magento 2026-06-17 N/A 7.5 HIGH
Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Authorization vulnerability that could lead in a security feature bypass in a way that an attacker could access unauthorised data. Exploitation of this issue does not require user interaction.
CVE-2023-38135 1 Intel 1 Performance Maximizer 2026-06-17 N/A 6.7 MEDIUM
Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2023-36611 1 Ovarro 10 Tbox Lt2, Tbox Lt2 Firmware, Tbox Ms-cpu32 and 7 more 2026-06-17 N/A 6.5 MEDIUM
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher privileges by establishing an SSH session and providing the other tokens.
CVE-2023-35022 1 Ibm 1 Infosphere Information Server 2026-06-17 N/A 3.3 LOW
IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: 258254.
CVE-2023-34460 3 Apple, Linux, Tauri 3 Macos, Linux Kernel, Tauri 2026-06-17 N/A 4.8 MEDIUM
Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by the glob wildcard scopes (eg. `$HOME/*`), but a regression was introduced when a configuration option for this behavior was implemented. Only Tauri applications using wildcard scopes in the `fs` endpoint are affected. The regression has been patched on version 1.4.1.
CVE-2023-33142 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 6.5 MEDIUM
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-32678 1 Zulip 1 Zulip Server 2026-06-17 N/A 6.5 MEDIUM
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit messages/topics, move messages to other streams, and delete messages that they used to have access to, if other relevant organization permissions allow these actions. For example, a user may be able to edit or delete their old messages they posted in such a private stream. An administrator will be able to delete old messages (that they had access to) from the private stream. This issue was fixed in Zulip Server version 7.3.
CVE-2023-32168 1 Dlink 1 D-view 8 2026-06-17 N/A 8.8 HIGH
D-Link D-View showUser Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of D-Link D-View. Authentication is required to exploit this vulnerability. The specific flaw exists within the showUser method. The issue results from the lack of proper authorization before accessing a privileged endpoint. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. . Was ZDI-CAN-19534.
CVE-2023-32022 1 Microsoft 4 Windows Server 2012, Windows Server 2016, Windows Server 2019 and 1 more 2026-06-17 N/A 7.6 HIGH
Windows Server Service Security Feature Bypass Vulnerability
CVE-2023-2950 1 Open-emr 1 Openemr 2026-06-17 N/A 8.1 HIGH
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2496 1 Granthweb 1 Go Pricing 2026-06-17 N/A 7.1 HIGH
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2023-2345 1 Oretnom23 1 Service Provider Management System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_inquiry. The manipulation leads to improper authorization. The attack may be launched remotely. The identifier of this vulnerability is VDB-227588.
CVE-2023-2227 1 Modoboa 1 Modoboa 2026-06-17 N/A 9.1 CRITICAL
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
CVE-2023-29338 1 Microsoft 1 Visual Studio Code 2026-06-17 N/A 6.6 MEDIUM
Visual Studio Code Spoofing Vulnerability
CVE-2023-28634 1 Glpi-project 1 Glpi 2026-06-17 N/A 8.8 HIGH
GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, a user who has the Technician profile could see and generate a Personal token for a Super-Admin. Using such token it is possible to negotiate a GLPI session and hijack the Super-Admin account, resulting in a Privilege Escalation. Versions 9.5.13 and 10.0.7 contain a patch for this issue.
CVE-2023-28325 1 Rocket.chat 1 Rocket.chat 2026-06-17 N/A 6.5 MEDIUM
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.
CVE-2023-28318 1 Rocket.chat 1 Rocket.chat 2026-06-17 N/A 5.3 MEDIUM
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.