Total
6050 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-37394 | 2 Deepak Anand, Wp Dummy Content Generator Project | 2 Wp Dummy Content Generator, Wp Dummy Content Generator | 2024-11-21 | 5.3 Medium |
| Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Generator: from n/a through 2.3.0. | ||||
| CVE-2023-37049 | 1 Emlog | 1 Emlog | 2024-11-21 | 6.5 Medium |
| emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php. | ||||
| CVE-2023-36815 | 1 Sealos | 1 Sealos | 2024-11-21 | 7.3 High |
| Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the ability to recharge any amount of 1 renminbi (RMB). The charging interface may expose resource information. The namespace of this custom resource would be user's control and may have permission to correct it. It is not clear whether a fix exists. | ||||
| CVE-2023-36695 | 1 Maximeschoeni | 1 Sublanguage | 2024-11-21 | 5.4 Medium |
| Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9. | ||||
| CVE-2023-36684 | 1 Brainstormforce | 1 Convert Pro | 2024-11-21 | 7.1 High |
| Missing Authorization vulnerability in Brainstorm Force Convert Pro.This issue affects Convert Pro: from n/a through 1.7.5. | ||||
| CVE-2023-36683 | 2024-11-21 | 6.5 Medium | ||
| Missing Authorization vulnerability in WP SCHEMA PRO Schema Pro.This issue affects Schema Pro: from n/a through 2.7.8. | ||||
| CVE-2023-36676 | 1 Brainstormforce | 1 Spectra | 2024-11-21 | 5.4 Medium |
| Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6. | ||||
| CVE-2023-36621 | 1 Nationaledtech | 1 Boomerang | 2024-11-21 | 9.1 Critical |
| An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing. | ||||
| CVE-2023-36516 | 1 Thimpress | 1 Learnpress | 2024-11-21 | 7.6 High |
| Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3. | ||||
| CVE-2023-36515 | 1 Thimpress | 1 Learnpress | 2024-11-21 | 7.3 High |
| Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3. | ||||
| CVE-2023-36140 | 1 Phpjabbers | 1 Cleaning Business Software | 2024-11-21 | 9.8 Critical |
| In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts. | ||||
| CVE-2023-36002 | 1 Proofpoint | 1 Insider Threat Management Server | 2024-11-21 | 4.3 Medium |
| A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected. | ||||
| CVE-2023-36000 | 2 Apple, Proofpoint | 2 Macos, Insider Threat Management Server | 2024-11-21 | 6.5 Medium |
| A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected. | ||||
| CVE-2023-35998 | 1 Proofpoint | 1 Insider Threat Management Server | 2024-11-21 | 4.6 Medium |
| A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected. | ||||
| CVE-2023-35940 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 7.5 High |
| GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue. | ||||
| CVE-2023-35937 | 1 Metersphere | 1 Metersphere | 2024-11-21 | 6 Medium |
| Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere lack permission checks. This allows ordinary users to execute APIs that can only be executed by space administrators or project administrators. For example, ordinary users can be updated as space administrators. Version 2.10.2 LTS has a patch for this issue. | ||||
| CVE-2023-35677 | 1 Google | 1 Android | 2024-11-21 | 5.5 Medium |
| In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2023-35665 | 1 Google | 1 Android | 2024-11-21 | 7.8 High |
| In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||||
| CVE-2023-35164 | 1 Dataease | 1 Dataease | 2024-11-21 | 6.3 Medium |
| DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability. | ||||
| CVE-2023-35049 | 2024-11-21 | 7.5 High | ||
| Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0. | ||||