Total
29929 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-23055 | 1 Plone | 1 Plone Docker Official Image | 2026-07-09 | N/A | 6.1 MEDIUM |
| An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers. | |||||
| CVE-2024-22902 | 1 Vinchin | 1 Vinchin Backup And Recovery | 2026-07-09 | N/A | 9.8 CRITICAL |
| Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials. | |||||
| CVE-2024-22901 | 1 Vinchin | 1 Vinchin Backup And Recovery | 2026-07-09 | N/A | 9.8 CRITICAL |
| Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials. | |||||
| CVE-2023-47327 | 1 Silverpeas | 1 Silverpeas | 2026-07-09 | N/A | 4.3 MEDIUM |
| The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL. | |||||
| CVE-2023-47325 | 1 Silverpeas | 1 Silverpeas | 2026-07-09 | N/A | 5.4 MEDIUM |
| Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces. | |||||
| CVE-2023-47323 | 1 Silverpeas | 1 Silverpeas | 2026-07-09 | N/A | 7.5 HIGH |
| The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators. | |||||
| CVE-2023-47321 | 1 Silverpeas | 1 Silverpeas | 2026-07-09 | N/A | 4.9 MEDIUM |
| Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets. | |||||
| CVE-2023-47320 | 1 Silverpeas | 1 Silverpeas | 2026-07-09 | N/A | 8.1 HIGH |
| Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below. | |||||
| CVE-2023-43336 | 1 Sangoma | 1 Freepbx | 2026-07-09 | N/A | 8.8 HIGH |
| Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101. | |||||
| CVE-2023-43141 | 1 Totolink | 4 A3700r, A3700r Firmware, N600r and 1 more | 2026-07-09 | N/A | 9.8 CRITICAL |
| TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control. | |||||
| CVE-2023-34673 | 1 Elenos | 2 Etg150, Etg150 Firmware | 2026-07-09 | N/A | 6.5 MEDIUM |
| Elenos ETG150 FM transmitter running on version 3.12 was discovered to be leaking SMTP credentials and other sensitive information by exploiting the publicly accessible Memcached service. The attack can occur over the public Internet in some cases. | |||||
| CVE-2023-34672 | 1 Elenos | 2 Etg150, Etg150 Firmware | 2026-07-09 | N/A | 8.8 HIGH |
| Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Internet in some cases. | |||||
| CVE-2023-34671 | 1 Elenos | 2 Etg150 Fm, Etg150 Fm Firmware | 2026-07-09 | N/A | 8.8 HIGH |
| Improper Access Control leads to privilege escalation affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role in the user profile. An attack could occur over the public Internet in some cases. | |||||
| CVE-2023-29818 | 1 Webroot | 1 Secureanywhere | 2026-07-09 | N/A | 5.5 MEDIUM |
| An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via the default allowlist feature being stored as non-admin. | |||||
| CVE-2022-47003 | 1 Murasoftware | 1 Mura Cms | 2026-07-09 | N/A | 9.8 CRITICAL |
| A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. | |||||
| CVE-2022-45552 | 1 Zbt | 2 We1626, We1626 Firmware | 2026-07-09 | N/A | 7.5 HIGH |
| An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information via SPI bus interface connected to pinout of the NAND flash memory. | |||||
| CVE-2022-45287 | 1 Temenos | 1 Cwx | 2026-07-09 | N/A | 8.8 HIGH |
| An access control issue in Registration.aspx of Temenos CWX 8.5.6 allows authenticated attackers to escalate privileges and perform arbitrary Administrative commands. | |||||
| CVE-2022-32993 | 1 Totolink | 2 A7000r, A7000r Firmware | 2026-07-09 | N/A | 9.8 CRITICAL |
| TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh. | |||||
| CVE-2022-28093 | 1 Online Sports Complex Booking System Project | 1 Online Sports Complex Booking System | 2026-07-09 | 7.5 HIGH | 9.8 CRITICAL |
| SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file. | |||||
| CVE-2021-42627 | 1 Dlink | 8 Dir-615, Dir-615 Firmware, Dir-615 J1 and 5 more | 2026-07-09 | N/A | 9.8 CRITICAL |
| The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page. | |||||
