Skip to main content

CWE archive

CWE-281 CVEs

Programmatic archive

339 CVEs tagged with CWE-28131 Critical, 148 High, 133 Medium, 25 Low, 2 Unrated.

CVE-2022-41963

Published Dec 16, 2022

BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that exists to handle delayed messages, but this grace period co…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-45446

Published Nov 2, 2022

A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folde…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41708

Published Oct 19, 2022

Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access existing chats in the workspaces of any user of the application. This is possible becau…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36062

Published Sep 22, 2022

Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resu…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38577

Published Sep 19, 2022

ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36102

Published Sep 12, 2022

Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a certain notation, the ACL could be bypassed. Users could execut…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2787

Published Aug 27, 2022

Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3414

Published Aug 26, 2022

A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also grant…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31237

Published Aug 22, 2022

Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permissions vulnerability in SyncIQ. A low privileged local atta…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-31262

Published Aug 17, 2022

An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folde…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32969

Published Jun 29, 2022

MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such f…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31096

Published Jun 27, 2022

Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an email that either doesn't match the invite's email or does…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3523

Published Apr 27, 2022

A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24428

Published Apr 8, 2022

Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local accou…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 339 CVEsPage 9 of 14