Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 28764 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-44543 1 In2code 1 Femanager 2023-12-14 N/A 5.3 MEDIUM
The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled.
CVE-2023-6547 1 Mattermost 1 Mattermost Server 2023-12-14 N/A 5.4 MEDIUM
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 
CVE-2023-6538 1 Hitachi 2 System Management Unit, System Management Unit Firmware 2023-12-14 N/A 6.5 MEDIUM
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.
CVE-2023-46389 1 Loytec 4 Linx-151, Linx-151 Firmware, Linx-212 and 1 more 2023-12-14 N/A 7.5 HIGH
LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.
CVE-2023-46387 1 Loytec 4 Linx-151, Linx-151 Firmware, Linx-212 and 1 more 2023-12-14 N/A 7.5 HIGH
LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 firmware 7.2.4 are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers to disclose sensitive information on Loytec device data point configuration.
CVE-2023-42580 1 Samsung 1 Galaxy Store 2023-12-12 N/A 9.8 CRITICAL
Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.
CVE-2023-42581 1 Samsung 1 Galaxy Store 2023-12-12 N/A 7.5 HIGH
Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.
CVE-2023-48860 1 Totolink 2 N300rt, N300rt Firmware 2023-12-12 N/A 9.8 CRITICAL
TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code.
CVE-2023-49246 1 Huawei 2 Emui, Harmonyos 2023-12-12 N/A 7.5 HIGH
Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-49245 1 Huawei 2 Emui, Harmonyos 2023-12-12 N/A 7.5 HIGH
Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-6566 1 Microweber 1 Microweber 2023-12-12 N/A 6.5 MEDIUM
Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.
CVE-2023-49248 1 Huawei 2 Emui, Harmonyos 2023-12-12 N/A 5.5 MEDIUM
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
CVE-2023-30589 2 Fedoraproject, Nodejs 2 Fedora, Node.js 2023-12-12 N/A 7.5 HIGH
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20
CVE-2023-28876 1 Afian 1 Filerun 2023-12-11 N/A 4.3 MEDIUM
A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delete comments on files uploaded by other users.
CVE-2023-45210 1 Pleasanter 1 Pleasanter 2023-12-11 N/A 4.3 MEDIUM
Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other users who are not permitted to access.
CVE-2023-48849 1 Ruijie 42 Rg-eg1000c, Rg-eg1000c Firmware, Rg-eg1000e and 39 more 2023-12-11 N/A 9.8 CRITICAL
Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.
CVE-2023-42574 1 Samsung 1 Gamehomecn 2023-12-11 N/A 7.8 HIGH
Improper access control vulnerablility in GameHomeCN prior to version 4.2.60.2 allows local attackers to launch arbitrary activity in GameHomeCN.
CVE-2023-42577 1 Samsung 2 Android, Samsung Voice Recorder 2023-12-11 N/A 2.4 LOW
Improper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allows physical attackers to access Voice Recorder information on the lock screen.
CVE-2023-44288 1 Dell 1 Powerscale Onefs 2023-12-11 N/A 7.5 HIGH
Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, leading to denial of service.
CVE-2023-44295 1 Dell 1 Powerscale Onefs 2023-12-11 N/A 8.1 HIGH
Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially exploit this vulnerability, leading to loss of information, and information disclosure.