Vulnerabilities (CVE)

Filtered by CWE-285
Total 1050 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-7463 1 Ibm 1 Business Process Manager 2026-06-17 5.5 MEDIUM 4.3 MEDIUM
IBM Business Process Manager 7.5.x, 8.0.x, 8.5.0, 8.5.5, and 8.5.6.0 through cumulative fix 2 allow remote authenticated users to delete process and task data by leveraging incorrect authorization checks. IBM X-Force ID: 108393.
CVE-2015-5463 1 Axiomsl 1 Axiom 2026-06-17 7.5 HIGH 9.8 CRITICAL
AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and earlier allows remote attackers to (1) access data of other basic users through arbitrary SQL commands, (2) perform a horizontal and vertical privilege escalation, (3) cause a Denial of Service on global application, or (4) write/read/delete arbitrary files on server hosting the application.
CVE-2015-3954 1 Pifzer 6 Plum A\+3 Infusion System, Plum A\+3 Infusion System Firmware, Plum A\+ Infusion System and 3 more 2026-06-17 10.0 HIGH 9.8 CRITICAL
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unauthorized user could issue commands to the pump. Hospira recommends that customers close Port 23/TELNET on the affected devices. Hospira has also released the Plum 360 Infusion System which is not vulnerable to this issue.
CVE-2015-3656 1 Arubanetworks 1 Clearpass 2026-06-17 6.5 MEDIUM 7.2 HIGH
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.
CVE-2015-1000007 1 Wptf-image-gallery Project 1 Wptf-image-gallery 2026-06-17 5.0 MEDIUM 7.5 HIGH
Remote file download vulnerability in wptf-image-gallery v1.03
CVE-2014-9950 1 Google 1 Android 2026-06-17 9.3 HIGH 7.8 HIGH
In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.
CVE-2014-9945 1 Google 1 Android 2026-06-17 9.3 HIGH 7.8 HIGH
In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.
CVE-2014-6049 1 Phpmyfaq 1 Phpmyfaq 2026-06-17 5.5 MEDIUM 2.7 LOW
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.
CVE-2014-2349 1 Emerson 1 Deltav 2026-06-17 6.2 MEDIUM N/A
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.
CVE-2013-7245 1 Sybase 1 Adaptive Server Enterprise 2026-06-17 5.0 MEDIUM 7.5 HIGH
The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP Security Note 1927859.