Vulnerabilities (CVE)

Filtered by CWE-286
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3907 1 Gitlab 1 Gitlab 2026-06-17 N/A 4.9 MEDIUM
A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner
CVE-2023-3115 1 Gitlab 1 Gitlab 2026-06-17 N/A 5.4 MEDIUM
An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.
CVE-2023-26689 1 Cs-cart 1 Cs-cart Multivendor 2026-06-17 N/A 9.8 CRITICAL
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
CVE-2022-35503 2026-06-17 N/A 7.5 HIGH
Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the OSM components, retrieve confidential information, or gain access other parts of a Telco Operator infrastructure other than OSM itself.
CVE-2021-26262 1 Philips 4 Mri 1.5t, Mri 1.5t Firmware, Mri 3t and 1 more 2026-06-17 5.0 MEDIUM 5.5 MEDIUM
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.