Total
2049 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2017-15200 | 1 Kanboard | 1 Kanboard | 2026-06-17 | 4.0 MEDIUM | 4.3 MEDIUM |
| In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user. | |||||
| CVE-2017-15199 | 1 Kanboard | 1 Kanboard | 2026-06-17 | 4.0 MEDIUM | 4.3 MEDIUM |
| In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description. | |||||
| CVE-2017-15197 | 1 Kanboard | 1 Kanboard | 2026-06-17 | 4.0 MEDIUM | 4.3 MEDIUM |
| In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user. | |||||
| CVE-2017-15196 | 1 Kanboard | 1 Kanboard | 2026-06-17 | 4.0 MEDIUM | 4.3 MEDIUM |
| In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user. | |||||
| CVE-2017-15195 | 1 Kanboard | 1 Kanboard | 2026-06-17 | 4.0 MEDIUM | 4.3 MEDIUM |
| In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user. | |||||
| CVE-2017-0936 | 1 Nextcloud | 1 Nextcloud Server | 2026-06-17 | 4.9 MEDIUM | 5.7 MEDIUM |
| Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user. | |||||
| CVE-2016-20033 | 1 Wowza | 1 Streaming Engine | 2026-06-17 | N/A | 7.8 HIGH |
| Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine service directories with malicious executables to execute code with LocalSystem privileges when services restart. | |||||
| CVE-2014-8356 | 1 Dasanzhone | 2 Znid 2426a, Znid 2426a Firmware | 2026-06-17 | 6.5 MEDIUM | 8.8 HIGH |
| The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference. | |||||
| CVE-2012-5571 | 1 Openstack | 2 Essex, Folsom | 2026-06-16 | 3.5 LOW | 5.4 MEDIUM |
| A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access. | |||||
