Перейти к содержимому
Noroxi

CWE-286 · 30 записей

Incorrect User Management

CVE этого класса

30 записей

  • CVE-2022-32260
    39Наблюдать

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    siemens · sinema remote connect server14 июн. 2022 г.

  • CVE-2023-26689
    39Наблюдать

    An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cs-cart · cs-cart multivendor24 сент. 2024 г.

  • CVE-2024-48853
    38Наблюдать

    Authenticated Escalation to guest to root

    КритическаяCVSS 9,5Эксплойта нетEPSS 0 %

    abb · aspect-enterprise22 мая 2025 г.

  • CVE-2023-3907
    35Наблюдать

    Improper User Management in GitLab

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    gitlab · gitlab17 дек. 2023 г.

  • CVE-2024-52359
    35Наблюдать

    IBM Concert Software improper access controls

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    ibm · concert19 нояб. 2024 г.

  • CVE-2021-21553
    35Наблюдать

    Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    dell · powerscale onefs2 авг. 2021 г.

  • CVE-2026-35638
    34Наблюдать

    OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    openclaw · openclaw9 апр. 2026 г.

  • CVE-2025-7972
    33Наблюдать

    Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability

    ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %

    rockwellautomation · factorytalk linx14 авг. 2025 г.

  • CVE-2026-56428
    32Наблюдать

    The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default con

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    bosch · bsh elp (electronic platform) modules30 июл. 2026 г.

  • CVE-2024-28020
    32Наблюдать

    A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management.

    ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %

    hitachienergy · foxman-un11 июн. 2024 г.

  • CVE-2023-25519
    31Наблюдать

    NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrec

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    nvidia · bluefield 1 firmware11 сент. 2023 г.

  • CVE-2024-58105
    31Наблюдать

    A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing s

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    trendmicro · apex one25 мар. 2025 г.

  • CVE-2023-0857
    30Наблюдать

    Unintentional change of settings during initial registration of system administrators which uses control protocols.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    canon · mf642cdw firmware11 мая 2023 г.

  • CVE-2022-45857
    30Наблюдать

    An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attack

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    fortinet · fortimanager5 янв. 2023 г.

  • CVE-2024-46671
    28Наблюдать

    An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below,

    ВысокаяCVSS 7,2Proof of conceptEPSS 0 %

    fortinet · fortiweb8 апр. 2025 г.

  • CVE-2026-60135
    28Наблюдать

    Weintek cMT3092X Incorrect User Management

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    weintek · cmt3092x firmware24 июл. 2026 г.

  • CVE-2024-27269
    27Наблюдать

    IBM QRadar SIEM information disclosure

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    ibm · qradar security information and event manager14 мая 2024 г.

  • CVE-2023-3932
    26Наблюдать

    Incorrect User Management in GitLab

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    gitlab · gitlab3 авг. 2023 г.

  • CVE-2024-45425
    26Наблюдать

    Zoom Workplace Apps - Incorrect User Management

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    zoom · meeting software development kit25 февр. 2025 г.

  • CVE-2025-63563
    26Наблюдать

    Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password ch

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    summerpearlgroup · vacation rental management platform31 окт. 2025 г.

  • CVE-2024-9312
    25Наблюдать

    Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions.

    СредняяCVSS 6,4Эксплойта нетEPSS 0 %

    canonical · authd10 окт. 2024 г.

  • CVE-2021-26262
    23Наблюдать

    Philips MRI 1.5T and 3T Improper Access Control

    СредняяCVSS 5,9Эксплойта нетEPSS 1 %

    philips · mri 3t firmware19 нояб. 2021 г.

  • CVE-2023-20253
    22Наблюдать

    A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacke

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    cisco · catalyst sd-wan manager27 сент. 2023 г.

  • CVE-2024-29296
    21Наблюдать

    A user enumeration vulnerability was found in Portainer CE 2.19.4.

    СредняяCVSS 5,3Proof of conceptEPSS 1 %

    portainer · portainer10 апр. 2024 г.

  • CVE-2023-3914
    21Наблюдать

    Incorrect User Management in GitLab

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    gitlab · gitlab29 сент. 2023 г.

Все классы уязвимостей