CWE-286 · 30 записей
Incorrect User Management
CVE этого класса
30 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-32260Эксплойта нет | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).siemens · sinema remote connect server · CWE-286 | Критическая9,8 | — | 0,7 % | 14 июн. 2022 г. |
39Наблюдать | CVE-2023-26689Эксплойта нет | An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.cs-cart · cs-cart multivendor · CWE-286 | Критическая9,8 | — | 0,6 % | 24 сент. 2024 г. |
38Наблюдать | CVE-2024-48853Эксплойта нет | Authenticated Escalation to guest to rootabb · aspect-enterprise · CWE-286 | Критическая9,5 | — | 0,4 % | 22 мая 2025 г. |
35Наблюдать | CVE-2023-3907Эксплойта нет | Improper User Management in GitLabgitlab · gitlab · CWE-286 | Высокая8,8 | — | 0,7 % | 17 дек. 2023 г. |
35Наблюдать | CVE-2024-52359Эксплойта нет | IBM Concert Software improper access controlsibm · concert · CWE-286 | Высокая8,8 | — | 0,3 % | 19 нояб. 2024 г. |
35Наблюдать | CVE-2021-21553Эксплойта нет | Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allowdell · powerscale onefs · CWE-286 | Высокая8,8 | — | 0,2 % | 2 авг. 2021 г. |
34Наблюдать | CVE-2026-35638Эксплойта нет | OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UIopenclaw · openclaw · CWE-286 | Высокая8,7 | — | 0,5 % | 9 апр. 2026 г. |
33Наблюдать | CVE-2025-7972Эксплойта нет | Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerabilityrockwellautomation · factorytalk linx · CWE-286 | Высокая8,4 | — | 0,5 % | 14 авг. 2025 г. |
32Наблюдать | CVE-2026-56428Эксплойта нет | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default conbosch · bsh elp (electronic platform) modules · CWE-286 | Высокая8,1 | — | 0,5 % | 30 июл. 2026 г. |
32Наблюдать | CVE-2024-28020Эксплойта нет | A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management.hitachienergy · foxman-un · CWE-286 | Высокая8,0 | — | 0,4 % | 11 июн. 2024 г. |
31Наблюдать | CVE-2023-25519Эксплойта нет | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrecnvidia · bluefield 1 firmware · CWE-286 | Высокая7,8 | — | 0,2 % | 11 сент. 2023 г. |
31Наблюдать | CVE-2024-58105Эксплойта нет | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing strendmicro · apex one · CWE-286 | Высокая7,8 | — | 0,2 % | 25 мар. 2025 г. |
30Наблюдать | CVE-2023-0857Эксплойта нет | Unintentional change of settings during initial registration of system administrators which uses control protocols.canon · mf642cdw firmware · CWE-286 | Высокая7,5 | — | 0,6 % | 11 мая 2023 г. |
30Наблюдать | CVE-2022-45857Эксплойта нет | An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attackfortinet · fortimanager · CWE-286 | Высокая7,5 | — | 0,3 % | 5 янв. 2023 г. |
28Наблюдать | CVE-2024-46671Proof of concept | An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below,fortinet · fortiweb · CWE-286 | Высокая7,2 | — | 0,4 % | 8 апр. 2025 г. |
28Наблюдать | CVE-2026-60135Эксплойта нет | Weintek cMT3092X Incorrect User Managementweintek · cmt3092x firmware · CWE-286 | Высокая7,1 | — | 0,4 % | 24 июл. 2026 г. |
27Наблюдать | CVE-2024-27269Эксплойта нет | IBM QRadar SIEM information disclosureibm · qradar security information and event manager · CWE-286 | Средняя6,8 | — | 0,4 % | 14 мая 2024 г. |
26Наблюдать | CVE-2023-3932Эксплойта нет | Incorrect User Management in GitLabgitlab · gitlab · CWE-286 | Средняя6,5 | — | 0,9 % | 3 авг. 2023 г. |
26Наблюдать | CVE-2024-45425Эксплойта нет | Zoom Workplace Apps - Incorrect User Managementzoom · meeting software development kit · CWE-286 | Средняя6,5 | — | 0,3 % | 25 февр. 2025 г. |
26Наблюдать | CVE-2025-63563Эксплойта нет | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password chsummerpearlgroup · vacation rental management platform · CWE-286 | Средняя6,5 | — | 0,3 % | 31 окт. 2025 г. |
25Наблюдать | CVE-2024-9312Эксплойта нет | Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions.canonical · authd · CWE-286 | Средняя6,4 | — | 0,3 % | 10 окт. 2024 г. |
23Наблюдать | CVE-2021-26262Эксплойта нет | Philips MRI 1.5T and 3T Improper Access Controlphilips · mri 3t firmware · CWE-286 | Средняя5,9 | — | 0,7 % | 19 нояб. 2021 г. |
22Наблюдать | CVE-2023-20253Эксплойта нет | A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attackecisco · catalyst sd-wan manager · CWE-286 | Средняя5,5 | — | 0,2 % | 27 сент. 2023 г. |
21Наблюдать | CVE-2024-29296Proof of concept | A user enumeration vulnerability was found in Portainer CE 2.19.4.portainer · portainer · CWE-286 | Средняя5,3 | — | 1,3 % | 10 апр. 2024 г. |
21Наблюдать | CVE-2023-3914Эксплойта нет | Incorrect User Management in GitLabgitlab · gitlab · CWE-286 | Средняя5,3 | — | 0,4 % | 29 сент. 2023 г. |
- CVE-2022-3226039Наблюдать
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %siemens · sinema remote connect server14 июн. 2022 г.
- CVE-2023-2668939Наблюдать
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cs-cart · cs-cart multivendor24 сент. 2024 г.
- CVE-2024-4885338Наблюдать
Authenticated Escalation to guest to root
КритическаяCVSS 9,5Эксплойта нетEPSS 0 %abb · aspect-enterprise22 мая 2025 г.
- CVE-2023-390735Наблюдать
Improper User Management in GitLab
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gitlab · gitlab17 дек. 2023 г.
- CVE-2024-5235935Наблюдать
IBM Concert Software improper access controls
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ibm · concert19 нояб. 2024 г.
- CVE-2021-2155335Наблюдать
Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %dell · powerscale onefs2 авг. 2021 г.
- CVE-2026-3563834Наблюдать
OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %openclaw · openclaw9 апр. 2026 г.
- CVE-2025-797233Наблюдать
Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %rockwellautomation · factorytalk linx14 авг. 2025 г.
- CVE-2026-5642832Наблюдать
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default con
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %bosch · bsh elp (electronic platform) modules30 июл. 2026 г.
- CVE-2024-2802032Наблюдать
A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management.
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %hitachienergy · foxman-un11 июн. 2024 г.
- CVE-2023-2551931Наблюдать
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrec
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %nvidia · bluefield 1 firmware11 сент. 2023 г.
- CVE-2024-5810531Наблюдать
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing s
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %trendmicro · apex one25 мар. 2025 г.
- CVE-2023-085730Наблюдать
Unintentional change of settings during initial registration of system administrators which uses control protocols.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %canon · mf642cdw firmware11 мая 2023 г.
- CVE-2022-4585730Наблюдать
An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attack
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %fortinet · fortimanager5 янв. 2023 г.
- CVE-2024-4667128Наблюдать
An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below,
ВысокаяCVSS 7,2Proof of conceptEPSS 0 %fortinet · fortiweb8 апр. 2025 г.
- CVE-2026-6013528Наблюдать
Weintek cMT3092X Incorrect User Management
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %weintek · cmt3092x firmware24 июл. 2026 г.
- CVE-2024-2726927Наблюдать
IBM QRadar SIEM information disclosure
СредняяCVSS 6,8Эксплойта нетEPSS 0 %ibm · qradar security information and event manager14 мая 2024 г.
- CVE-2023-393226Наблюдать
Incorrect User Management in GitLab
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gitlab · gitlab3 авг. 2023 г.
- CVE-2024-4542526Наблюдать
Zoom Workplace Apps - Incorrect User Management
СредняяCVSS 6,5Эксплойта нетEPSS 0 %zoom · meeting software development kit25 февр. 2025 г.
- CVE-2025-6356326Наблюдать
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password ch
СредняяCVSS 6,5Эксплойта нетEPSS 0 %summerpearlgroup · vacation rental management platform31 окт. 2025 г.
- CVE-2024-931225Наблюдать
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions.
СредняяCVSS 6,4Эксплойта нетEPSS 0 %canonical · authd10 окт. 2024 г.
- CVE-2021-2626223Наблюдать
Philips MRI 1.5T and 3T Improper Access Control
СредняяCVSS 5,9Эксплойта нетEPSS 1 %philips · mri 3t firmware19 нояб. 2021 г.
- CVE-2023-2025322Наблюдать
A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacke
СредняяCVSS 5,5Эксплойта нетEPSS 0 %cisco · catalyst sd-wan manager27 сент. 2023 г.
- CVE-2024-2929621Наблюдать
A user enumeration vulnerability was found in Portainer CE 2.19.4.
СредняяCVSS 5,3Proof of conceptEPSS 1 %portainer · portainer10 апр. 2024 г.
- CVE-2023-391421Наблюдать
Incorrect User Management in GitLab
СредняяCVSS 5,3Эксплойта нетEPSS 0 %gitlab · gitlab29 сент. 2023 г.