CWE-286 · 30 records
Incorrect User Management
CVEs in this class
30 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-32260No exploit | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).siemens · sinema remote connect server · CWE-286 | Critical9.8 | — | 0.7% | Jun 14, 2022 |
39Monitor | CVE-2023-26689No exploit | An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.cs-cart · cs-cart multivendor · CWE-286 | Critical9.8 | — | 0.6% | Sep 24, 2024 |
38Monitor | CVE-2024-48853No exploit | Authenticated Escalation to guest to rootabb · aspect-enterprise · CWE-286 | Critical9.5 | — | 0.4% | May 22, 2025 |
35Monitor | CVE-2023-3907No exploit | Improper User Management in GitLabgitlab · gitlab · CWE-286 | High8.8 | — | 0.7% | Dec 17, 2023 |
35Monitor | CVE-2024-52359No exploit | IBM Concert Software improper access controlsibm · concert · CWE-286 | High8.8 | — | 0.3% | Nov 19, 2024 |
35Monitor | CVE-2021-21553No exploit | Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allowdell · powerscale onefs · CWE-286 | High8.8 | — | 0.2% | Aug 2, 2021 |
34Monitor | CVE-2026-35638No exploit | OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UIopenclaw · openclaw · CWE-286 | High8.7 | — | 0.5% | Apr 9, 2026 |
33Monitor | CVE-2025-7972No exploit | Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerabilityrockwellautomation · factorytalk linx · CWE-286 | High8.4 | — | 0.5% | Aug 14, 2025 |
32Monitor | CVE-2026-56428No exploit | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default conbosch · bsh elp (electronic platform) modules · CWE-286 | High8.1 | — | 0.5% | Jul 30, 2026 |
32Monitor | CVE-2024-28020No exploit | A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management.hitachienergy · foxman-un · CWE-286 | High8.0 | — | 0.4% | Jun 11, 2024 |
31Monitor | CVE-2023-25519No exploit | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrecnvidia · bluefield 1 firmware · CWE-286 | High7.8 | — | 0.2% | Sep 11, 2023 |
31Monitor | CVE-2024-58105No exploit | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing strendmicro · apex one · CWE-286 | High7.8 | — | 0.2% | Mar 25, 2025 |
30Monitor | CVE-2023-0857No exploit | Unintentional change of settings during initial registration of system administrators which uses control protocols.canon · mf642cdw firmware · CWE-286 | High7.5 | — | 0.6% | May 11, 2023 |
30Monitor | CVE-2022-45857No exploit | An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attackfortinet · fortimanager · CWE-286 | High7.5 | — | 0.3% | Jan 5, 2023 |
28Monitor | CVE-2024-46671Proof of concept | An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below,fortinet · fortiweb · CWE-286 | High7.2 | — | 0.4% | Apr 8, 2025 |
28Monitor | CVE-2026-60135No exploit | Weintek cMT3092X Incorrect User Managementweintek · cmt3092x firmware · CWE-286 | High7.1 | — | 0.4% | Jul 24, 2026 |
27Monitor | CVE-2024-27269No exploit | IBM QRadar SIEM information disclosureibm · qradar security information and event manager · CWE-286 | Medium6.8 | — | 0.4% | May 14, 2024 |
26Monitor | CVE-2023-3932No exploit | Incorrect User Management in GitLabgitlab · gitlab · CWE-286 | Medium6.5 | — | 0.9% | Aug 3, 2023 |
26Monitor | CVE-2024-45425No exploit | Zoom Workplace Apps - Incorrect User Managementzoom · meeting software development kit · CWE-286 | Medium6.5 | — | 0.3% | Feb 25, 2025 |
26Monitor | CVE-2025-63563No exploit | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password chsummerpearlgroup · vacation rental management platform · CWE-286 | Medium6.5 | — | 0.2% | Oct 31, 2025 |
25Monitor | CVE-2024-9312No exploit | Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions.canonical · authd · CWE-286 | Medium6.4 | — | 0.3% | Oct 10, 2024 |
23Monitor | CVE-2021-26262No exploit | Philips MRI 1.5T and 3T Improper Access Controlphilips · mri 3t firmware · CWE-286 | Medium5.9 | — | 0.7% | Nov 19, 2021 |
22Monitor | CVE-2023-20253No exploit | A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attackecisco · catalyst sd-wan manager · CWE-286 | Medium5.5 | — | 0.2% | Sep 27, 2023 |
21Monitor | CVE-2024-29296Proof of concept | A user enumeration vulnerability was found in Portainer CE 2.19.4.portainer · portainer · CWE-286 | Medium5.3 | — | 1.3% | Apr 10, 2024 |
21Monitor | CVE-2023-3914No exploit | Incorrect User Management in GitLabgitlab · gitlab · CWE-286 | Medium5.3 | — | 0.4% | Sep 29, 2023 |
- CVE-2022-3226039Monitor
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).
CriticalCVSS 9.8No exploitEPSS 1%siemens · sinema remote connect serverJun 14, 2022
- CVE-2023-2668939Monitor
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
CriticalCVSS 9.8No exploitEPSS 1%cs-cart · cs-cart multivendorSep 24, 2024
- CVE-2024-4885338Monitor
Authenticated Escalation to guest to root
CriticalCVSS 9.5No exploitEPSS 0%abb · aspect-enterpriseMay 22, 2025
- CVE-2023-390735Monitor
Improper User Management in GitLab
HighCVSS 8.8No exploitEPSS 1%gitlab · gitlabDec 17, 2023
- CVE-2024-5235935Monitor
IBM Concert Software improper access controls
HighCVSS 8.8No exploitEPSS 0%ibm · concertNov 19, 2024
- CVE-2021-2155335Monitor
Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow
HighCVSS 8.8No exploitEPSS 0%dell · powerscale onefsAug 2, 2021
- CVE-2026-3563834Monitor
OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI
HighCVSS 8.7No exploitEPSS 1%openclaw · openclawApr 9, 2026
- CVE-2025-797233Monitor
Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability
HighCVSS 8.4No exploitEPSS 1%rockwellautomation · factorytalk linxAug 14, 2025
- CVE-2026-5642832Monitor
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default con
HighCVSS 8.1No exploitEPSS 0%bosch · bsh elp (electronic platform) modulesJul 30, 2026
- CVE-2024-2802032Monitor
A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management.
HighCVSS 8.0No exploitEPSS 0%hitachienergy · foxman-unJun 11, 2024
- CVE-2023-2551931Monitor
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrec
HighCVSS 7.8No exploitEPSS 0%nvidia · bluefield 1 firmwareSep 11, 2023
- CVE-2024-5810531Monitor
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing s
HighCVSS 7.8No exploitEPSS 0%trendmicro · apex oneMar 25, 2025
- CVE-2023-085730Monitor
Unintentional change of settings during initial registration of system administrators which uses control protocols.
HighCVSS 7.5No exploitEPSS 1%canon · mf642cdw firmwareMay 11, 2023
- CVE-2022-4585730Monitor
An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attack
HighCVSS 7.5No exploitEPSS 0%fortinet · fortimanagerJan 5, 2023
- CVE-2024-4667128Monitor
An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below,
HighCVSS 7.2Proof of conceptEPSS 0%fortinet · fortiwebApr 8, 2025
- CVE-2026-6013528Monitor
Weintek cMT3092X Incorrect User Management
HighCVSS 7.1No exploitEPSS 0%weintek · cmt3092x firmwareJul 24, 2026
- CVE-2024-2726927Monitor
IBM QRadar SIEM information disclosure
MediumCVSS 6.8No exploitEPSS 0%ibm · qradar security information and event managerMay 14, 2024
- CVE-2023-393226Monitor
Incorrect User Management in GitLab
MediumCVSS 6.5No exploitEPSS 1%gitlab · gitlabAug 3, 2023
- CVE-2024-4542526Monitor
Zoom Workplace Apps - Incorrect User Management
MediumCVSS 6.5No exploitEPSS 0%zoom · meeting software development kitFeb 25, 2025
- CVE-2025-6356326Monitor
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password ch
MediumCVSS 6.5No exploitEPSS 0%summerpearlgroup · vacation rental management platformOct 31, 2025
- CVE-2024-931225Monitor
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions.
MediumCVSS 6.4No exploitEPSS 0%canonical · authdOct 10, 2024
- CVE-2021-2626223Monitor
Philips MRI 1.5T and 3T Improper Access Control
MediumCVSS 5.9No exploitEPSS 1%philips · mri 3t firmwareNov 19, 2021
- CVE-2023-2025322Monitor
A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacke
MediumCVSS 5.5No exploitEPSS 0%cisco · catalyst sd-wan managerSep 27, 2023
- CVE-2024-2929621Monitor
A user enumeration vulnerability was found in Portainer CE 2.19.4.
MediumCVSS 5.3Proof of conceptEPSS 1%portainer · portainerApr 10, 2024
- CVE-2023-391421Monitor
Incorrect User Management in GitLab
MediumCVSS 5.3No exploitEPSS 0%gitlab · gitlabSep 29, 2023