Show filters
978 Total Results
Displaying 451-460 of 978
Sort by:
Attacker Value
Unknown
CVE-2021-37304
Disclosure Date: February 03, 2023 (last updated February 24, 2025)
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
0
Attacker Value
Unknown
CVE-2023-22326
Disclosure Date: February 01, 2023 (last updated February 24, 2025)
In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an authenticated attacker with resource administrator or administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
0
Attacker Value
Unknown
CVE-2022-44715
Disclosure Date: January 27, 2023 (last updated February 24, 2025)
Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.
0
Attacker Value
Unknown
CVE-2022-44263
Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.
0
Attacker Value
Unknown
CVE-2023-23610
Disclosure Date: January 26, 2023 (last updated February 24, 2025)
GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any user having access to the standard interface can export data of almost any GLPI item type, even those on which user is not allowed to access (including assets, tickets, users, ...). This issue is patched in 10.0.6.
0
Attacker Value
Unknown
CVE-2023-22592
Disclosure Date: January 18, 2023 (last updated February 24, 2025)
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permission settings. IBM X-Force ID: 244073.
0
Attacker Value
Unknown
CVE-2022-34457
Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path which leads to privilege escalation. This is critical severity vulnerability as it allows non-admin to modify the files inside installed directory and able to make application unavailable for all users.
0
Attacker Value
Unknown
CVE-2022-48257
Disclosure Date: January 13, 2023 (last updated February 24, 2025)
In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
0
Attacker Value
Unknown
CVE-2022-39186
Disclosure Date: January 12, 2023 (last updated February 24, 2025)
EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions
0
Attacker Value
Unknown
CVE-2022-47927
Disclosure Date: January 12, 2023 (last updated February 24, 2025)
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.
0