Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29929 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-23055 1 Plone 1 Plone Docker Official Image 2026-07-09 N/A 6.1 MEDIUM
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.
CVE-2024-22902 1 Vinchin 1 Vinchin Backup And Recovery 2026-07-09 N/A 9.8 CRITICAL
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
CVE-2024-22901 1 Vinchin 1 Vinchin Backup And Recovery 2026-07-09 N/A 9.8 CRITICAL
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
CVE-2023-47327 1 Silverpeas 1 Silverpeas 2026-07-09 N/A 4.3 MEDIUM
The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.
CVE-2023-47325 1 Silverpeas 1 Silverpeas 2026-07-09 N/A 5.4 MEDIUM
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
CVE-2023-47323 1 Silverpeas 1 Silverpeas 2026-07-09 N/A 7.5 HIGH
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.
CVE-2023-47321 1 Silverpeas 1 Silverpeas 2026-07-09 N/A 4.9 MEDIUM
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.
CVE-2023-47320 1 Silverpeas 1 Silverpeas 2026-07-09 N/A 8.1 HIGH
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
CVE-2023-43336 1 Sangoma 1 Freepbx 2026-07-09 N/A 8.8 HIGH
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.
CVE-2023-43141 1 Totolink 4 A3700r, A3700r Firmware, N600r and 1 more 2026-07-09 N/A 9.8 CRITICAL
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.
CVE-2023-34673 1 Elenos 2 Etg150, Etg150 Firmware 2026-07-09 N/A 6.5 MEDIUM
Elenos ETG150 FM transmitter running on version 3.12 was discovered to be leaking SMTP credentials and other sensitive information by exploiting the publicly accessible Memcached service. The attack can occur over the public Internet in some cases.
CVE-2023-34672 1 Elenos 2 Etg150, Etg150 Firmware 2026-07-09 N/A 8.8 HIGH
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Internet in some cases.
CVE-2023-34671 1 Elenos 2 Etg150 Fm, Etg150 Fm Firmware 2026-07-09 N/A 8.8 HIGH
Improper Access Control leads to privilege escalation affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role in the user profile. An attack could occur over the public Internet in some cases.
CVE-2023-29818 1 Webroot 1 Secureanywhere 2026-07-09 N/A 5.5 MEDIUM
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin.
CVE-2022-47003 1 Murasoftware 1 Mura Cms 2026-07-09 N/A 9.8 CRITICAL
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
CVE-2022-45552 1 Zbt 2 We1626, We1626 Firmware 2026-07-09 N/A 7.5 HIGH
An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information via SPI bus interface connected to pinout of the NAND flash memory.
CVE-2022-45287 1 Temenos 1 Cwx 2026-07-09 N/A 8.8 HIGH
An access control issue in Registration.aspx of Temenos CWX 8.5.6 allows authenticated attackers to escalate privileges and perform arbitrary Administrative commands.
CVE-2022-32993 1 Totolink 2 A7000r, A7000r Firmware 2026-07-09 N/A 9.8 CRITICAL
TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
CVE-2022-28093 1 Online Sports Complex Booking System Project 1 Online Sports Complex Booking System 2026-07-09 7.5 HIGH 9.8 CRITICAL
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
CVE-2021-42627 1 Dlink 8 Dir-615, Dir-615 Firmware, Dir-615 J1 and 5 more 2026-07-09 N/A 9.8 CRITICAL
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.