Show filters
313 Total Results
Displaying 41-50 of 313
Sort by:
Attacker Value
Unknown

CVE-2022-0170

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
peertube is vulnerable to Improper Access Control
Attacker Value
Unknown

CVE-2021-45034

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows access to logfiles and diagnostic data generated by a privileged user. An unauthenticated attacker could access the files by knowing the corresponding download links.
Attacker Value
Unknown

CVE-2021-23173

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.
Attacker Value
Unknown

CVE-2021-4194

Disclosure Date: January 06, 2022 (last updated February 23, 2025)
bookstack is vulnerable to Improper Access Control
Attacker Value
Unknown

CVE-2021-22567

Disclosure Date: January 05, 2022 (last updated February 23, 2025)
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.
Attacker Value
Unknown

CVE-2021-25991

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.
Attacker Value
Unknown

CVE-2021-20050

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
Attacker Value
Unknown

CVE-2021-42808

Disclosure Date: December 20, 2021 (last updated February 23, 2025)
Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges.
Attacker Value
Unknown

CVE-2022-23134

Disclosure Date: December 20, 2021 (last updated February 23, 2025)
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
Attacker Value
Unknown

CVE-2021-4119

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
bookstack is vulnerable to Improper Access Control