Skip to main content

CWE archive

CWE-281 CVEs

Programmatic archive

337 CVEs tagged with CWE-28131 Critical, 148 High, 132 Medium, 24 Low, 2 Unrated.

CVE-2024-22401

Published Jan 18, 2024

Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6239

Published Nov 28, 2023

Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48240

Published Nov 20, 2023

XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-43612

Published Nov 20, 2023

in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4996

Published Nov 6, 2023

Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a spe…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45807

Published Oct 16, 2023

OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana following the license change in early 2021. There is an issue with the implementation of tenant perm…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30735

Published Oct 4, 2023

Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47637

Published Sep 12, 2023

The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41939

Published Sep 6, 2023

Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional per…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1386

Published Jul 24, 2023

A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileg…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-34034

Published Jul 19, 2023

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a s…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-21249

Published Jul 13, 2023

In multiple functions of OneTimePermissionUserManager.java, there is a possible one-time permission retention due to a permissions bypass. This could lead to local escalation of p…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35938

Published Jun 29, 2023

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. When switching from a project visibility that allows restricted users to `Pr…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2818

Published Jun 27, 2023

An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32552

Published Jun 26, 2023

An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive in…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34672

Published Jun 23, 2023

Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32355

Published Jun 23, 2023

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may be able to modify pr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 337 CVEsPage 7 of 14