Skip to content
Noroxi

CWE-286 · 30 records

Incorrect User Management

CVEs in this class

30 records

  • A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).

    CriticalCVSS 9.8No exploitEPSS 1%

    siemens · sinema remote connect serverJun 14, 2022

  • An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

    CriticalCVSS 9.8No exploitEPSS 1%

    cs-cart · cs-cart multivendorSep 24, 2024

  • Authenticated Escalation to guest to root

    CriticalCVSS 9.5No exploitEPSS 0%

    abb · aspect-enterpriseMay 22, 2025

  • CVE-2023-3907
    35Monitor

    Improper User Management in GitLab

    HighCVSS 8.8No exploitEPSS 1%

    gitlab · gitlabDec 17, 2023

  • IBM Concert Software improper access controls

    HighCVSS 8.8No exploitEPSS 0%

    ibm · concertNov 19, 2024

  • Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow

    HighCVSS 8.8No exploitEPSS 0%

    dell · powerscale onefsAug 2, 2021

  • OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI

    HighCVSS 8.7No exploitEPSS 1%

    openclaw · openclawApr 9, 2026

  • CVE-2025-7972
    33Monitor

    Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability

    HighCVSS 8.4No exploitEPSS 1%

    rockwellautomation · factorytalk linxAug 14, 2025

  • The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default con

    HighCVSS 8.1No exploitEPSS 0%

    bosch · bsh elp (electronic platform) modulesJul 30, 2026

  • A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management.

    HighCVSS 8.0No exploitEPSS 0%

    hitachienergy · foxman-unJun 11, 2024

  • NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrec

    HighCVSS 7.8No exploitEPSS 0%

    nvidia · bluefield 1 firmwareSep 11, 2023

  • A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing s

    HighCVSS 7.8No exploitEPSS 0%

    trendmicro · apex oneMar 25, 2025

  • CVE-2023-0857
    30Monitor

    Unintentional change of settings during initial registration of system administrators which uses control protocols.

    HighCVSS 7.5No exploitEPSS 1%

    canon · mf642cdw firmwareMay 11, 2023

  • An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attack

    HighCVSS 7.5No exploitEPSS 0%

    fortinet · fortimanagerJan 5, 2023

  • An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below,

    HighCVSS 7.2Proof of conceptEPSS 0%

    fortinet · fortiwebApr 8, 2025

  • Weintek cMT3092X Incorrect User Management

    HighCVSS 7.1No exploitEPSS 0%

    weintek · cmt3092x firmwareJul 24, 2026

  • IBM QRadar SIEM information disclosure

    MediumCVSS 6.8No exploitEPSS 0%

    ibm · qradar security information and event managerMay 14, 2024

  • CVE-2023-3932
    26Monitor

    Incorrect User Management in GitLab

    MediumCVSS 6.5No exploitEPSS 1%

    gitlab · gitlabAug 3, 2023

  • Zoom Workplace Apps - Incorrect User Management

    MediumCVSS 6.5No exploitEPSS 0%

    zoom · meeting software development kitFeb 25, 2025

  • Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password ch

    MediumCVSS 6.5No exploitEPSS 0%

    summerpearlgroup · vacation rental management platformOct 31, 2025

  • CVE-2024-9312
    25Monitor

    Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions.

    MediumCVSS 6.4No exploitEPSS 0%

    canonical · authdOct 10, 2024

  • Philips MRI 1.5T and 3T Improper Access Control

    MediumCVSS 5.9No exploitEPSS 1%

    philips · mri 3t firmwareNov 19, 2021

  • A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacke

    MediumCVSS 5.5No exploitEPSS 0%

    cisco · catalyst sd-wan managerSep 27, 2023

  • A user enumeration vulnerability was found in Portainer CE 2.19.4.

    MediumCVSS 5.3Proof of conceptEPSS 1%

    portainer · portainerApr 10, 2024

  • CVE-2023-3914
    21Monitor

    Incorrect User Management in GitLab

    MediumCVSS 5.3No exploitEPSS 0%

    gitlab · gitlabSep 29, 2023

All vulnerability classes