Vulnerabilities (CVE)

Filtered by CWE-346
Total 609 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-32223 1 Dlink 2 Dsl-224, Dsl-224 Firmware 2026-06-17 N/A 8.8 HIGH
D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.
CVE-2023-30996 2 Ibm, Netapp 2 Cognos Analytics, Oncommand Insight 2026-06-17 N/A 5.3 MEDIUM
IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.
CVE-2023-30949 1 Palantir 1 Slate 2026-06-17 N/A 4.3 MEDIUM
A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.
CVE-2023-30856 1 Edex-ui Project 1 Edex-ui 2026-06-17 N/A 8.3 HIGH
eDEX-UI is a science fiction terminal emulator. Versions 2.2.8 and prior are vulnerable to cross-site websocket hijacking. When running eDEX-UI and browsing the web, a malicious website can connect to eDEX's internal terminal control websocket, and send arbitrary commands to the shell. The project has been archived since 2021, and as of time of publication there are no plans to patch this issue and release a new version. Some workarounds are available, including shutting down eDEX-UI when browsing the web and ensuring the eDEX terminal runs with lowest possible privileges.
CVE-2023-30196 1 Webbax 1 Salesbooster 2026-06-17 N/A 7.5 HIGH
Prestashop salesbooster <= 1.10.4 is vulnerable to Incorrect Access Control via modules/salesbooster/downloads/download.php.
CVE-2023-2850 1 Nodebb 1 Nodebb 2026-06-17 N/A 4.7 MEDIUM
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation of the request origin. Exploitation of this vulnerability allows certain user information to be extracted by attacker.
CVE-2023-2848 1 Movim 1 Movim 2026-06-17 N/A 8.0 HIGH
Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a missing header validation.
CVE-2023-2639 1 Rockwellautomation 2 Factorytalk Policy Manager, Factorytalk System Services 2026-06-17 N/A 4.1 MEDIUM
The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the communication is from a legitimate local client device.  This may allow a threat actor to craft a malicious website that, when visited, will send a malicious script that can connect to the local WebSocket endpoint and wait for events as if it was a valid client device. If successfully exploited, this would allow a threat actor to receive information including whether FactoryTalk Policy Manager is installed and potentially the entire security policy. 
CVE-2023-2589 1 Gitlab 1 Gitlab 2026-06-17 N/A 5.9 MEDIUM
An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group.
CVE-2023-2445 1 Devolutions 1 Devolutions Server 2026-06-17 N/A 4.9 MEDIUM
Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.
CVE-2023-29868 1 Zammad 1 Zammad 2026-06-17 N/A 6.5 MEDIUM
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker with agent and customer roles could perform unauthorized changes on articles where they only have customer permissions.
CVE-2023-29867 1 Zammad 1 Zammad 2026-06-17 N/A 6.5 MEDIUM
Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker could gain information about linked accounts of users involved in their tickets using the Zammad API.
CVE-2023-29756 1 Urbanandroid 1 Twilight 2026-06-17 N/A 5.5 MEDIUM
An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.
CVE-2023-29753 1 Ekatox 1 Facemoji\ 2026-06-17 N/A 5.5 MEDIUM
An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows a local attacker to cause a denial of service via the SharedPreference files.
CVE-2023-29751 1 Yandex 1 Navigator 2026-06-17 N/A 5.5 MEDIUM
An issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the SharedPreference files.
CVE-2023-29745 1 Bestweather Project 1 Bestweather 2026-06-17 N/A 7.1 HIGH
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.
CVE-2023-29743 1 Bestweather Project 1 Bestweather 2026-06-17 N/A 7.5 HIGH
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.
CVE-2023-29728 1 Applika 1 Call Blocker 2026-06-17 N/A 9.8 CRITICAL
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.
CVE-2023-29711 1 Interlink 2 Psg-5124, Psg-5124 Firmware 2026-06-17 N/A 9.8 CRITICAL
An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET request.
CVE-2023-29505 1 Zohocorp 1 Manageengine Network Configuration Manager 2026-06-17 N/A 4.3 MEDIUM
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.