Show filters
776 Total Results
Displaying 131-140 of 776
Sort by:
Attacker Value
Unknown
CVE-2023-28051
Disclosure Date: April 07, 2023 (last updated February 24, 2025)
Dell Power Manager, versions 3.10 and prior, contains an Improper Access Control vulnerability. A low-privileged attacker could potentially exploit this vulnerability to elevate privileges on the system.
0
Attacker Value
Unknown
CVE-2023-0319
Disclosure Date: April 05, 2023 (last updated February 24, 2025)
An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.
0
Attacker Value
Unknown
CVE-2023-1883
Disclosure Date: April 05, 2023 (last updated February 24, 2025)
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
0
Attacker Value
Unknown
CVE-2023-28845
Disclosure Date: March 31, 2023 (last updated February 24, 2025)
Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members. It is recommended that the Nextcloud Talk is upgraded to 14.0.9 or 15.0.4. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-28844
Disclosure Date: March 31, 2023 (last updated February 24, 2025)
Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been addressed in versions 24.0.10 and 25.0.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-28645
Disclosure Date: March 31, 2023 (last updated February 24, 2025)
Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich documents app can be bypassed by using unprotected internal API endpoint of the rich documents app. It is recommended that the Nextcloud Office app (richdocuments) is upgraded to 8.0.0-beta.1, 7.0.2 or 6.3.2. Users unable to upgrade may mitigate the issue by taking steps to restrict the ability to download documents. This includes ensuring that the `WOPI configuration` is configured to only serve documents between Nextcloud and Collabora. It is highly recommended to define the list of Collabora server IPs as the allow list within the Office admin settings of Nextcloud.
0
Attacker Value
Unknown
CVE-2023-29140
Disclosure Date: March 31, 2023 (last updated February 24, 2025)
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. Attackers might be able to see edits for which the username has been hidden, because there is no check for rev_deleted.
0
Attacker Value
Unknown
CVE-2023-28877
Disclosure Date: March 31, 2023 (last updated February 24, 2025)
The VTEX apps-graphql@2.x GraphQL API module does not properly restrict unauthorized access to private configuration data. (apps-graphql@3.x is unaffected by this issue.)
0
Attacker Value
Unknown
CVE-2022-47542
Disclosure Date: March 30, 2023 (last updated February 24, 2025)
Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.
0
Attacker Value
Unknown
CVE-2022-24972
Disclosure Date: March 28, 2023 (last updated February 24, 2025)
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of proper access control. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-13911.
0