CWE-286 · 30 kayıt
Incorrect User Management
Bu sınıftaki CVE’ler
30 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-32260İstismar yok | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).siemens · sinema remote connect server · CWE-286 | Kritik9,8 | — | %0,7 | 14 Haz 2022 |
39İzleyin | CVE-2023-26689İstismar yok | An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.cs-cart · cs-cart multivendor · CWE-286 | Kritik9,8 | — | %0,6 | 24 Eyl 2024 |
38İzleyin | CVE-2024-48853İstismar yok | Authenticated Escalation to guest to rootabb · aspect-enterprise · CWE-286 | Kritik9,5 | — | %0,4 | 22 May 2025 |
35İzleyin | CVE-2023-3907İstismar yok | Improper User Management in GitLabgitlab · gitlab · CWE-286 | Yüksek8,8 | — | %0,7 | 17 Ara 2023 |
35İzleyin | CVE-2024-52359İstismar yok | IBM Concert Software improper access controlsibm · concert · CWE-286 | Yüksek8,8 | — | %0,3 | 19 Kas 2024 |
35İzleyin | CVE-2021-21553İstismar yok | Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allowdell · powerscale onefs · CWE-286 | Yüksek8,8 | — | %0,2 | 2 Ağu 2021 |
34İzleyin | CVE-2026-35638İstismar yok | OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UIopenclaw · openclaw · CWE-286 | Yüksek8,7 | — | %0,5 | 9 Nis 2026 |
33İzleyin | CVE-2025-7972İstismar yok | Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerabilityrockwellautomation · factorytalk linx · CWE-286 | Yüksek8,4 | — | %0,5 | 14 Ağu 2025 |
32İzleyin | CVE-2026-56428İstismar yok | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default conbosch · bsh elp (electronic platform) modules · CWE-286 | Yüksek8,1 | — | %0,5 | 30 Tem 2026 |
32İzleyin | CVE-2024-28020İstismar yok | A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management.hitachienergy · foxman-un · CWE-286 | Yüksek8,0 | — | %0,4 | 11 Haz 2024 |
31İzleyin | CVE-2023-25519İstismar yok | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrecnvidia · bluefield 1 firmware · CWE-286 | Yüksek7,8 | — | %0,2 | 11 Eyl 2023 |
31İzleyin | CVE-2024-58105İstismar yok | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing strendmicro · apex one · CWE-286 | Yüksek7,8 | — | %0,2 | 25 Mar 2025 |
30İzleyin | CVE-2023-0857İstismar yok | Unintentional change of settings during initial registration of system administrators which uses control protocols.canon · mf642cdw firmware · CWE-286 | Yüksek7,5 | — | %0,6 | 11 May 2023 |
30İzleyin | CVE-2022-45857İstismar yok | An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attackfortinet · fortimanager · CWE-286 | Yüksek7,5 | — | %0,3 | 5 Oca 2023 |
28İzleyin | CVE-2024-46671Kavram kanıtı | An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below,fortinet · fortiweb · CWE-286 | Yüksek7,2 | — | %0,4 | 8 Nis 2025 |
28İzleyin | CVE-2026-60135İstismar yok | Weintek cMT3092X Incorrect User Managementweintek · cmt3092x firmware · CWE-286 | Yüksek7,1 | — | %0,4 | 24 Tem 2026 |
27İzleyin | CVE-2024-27269İstismar yok | IBM QRadar SIEM information disclosureibm · qradar security information and event manager · CWE-286 | Orta6,8 | — | %0,4 | 14 May 2024 |
26İzleyin | CVE-2023-3932İstismar yok | Incorrect User Management in GitLabgitlab · gitlab · CWE-286 | Orta6,5 | — | %0,9 | 3 Ağu 2023 |
26İzleyin | CVE-2024-45425İstismar yok | Zoom Workplace Apps - Incorrect User Managementzoom · meeting software development kit · CWE-286 | Orta6,5 | — | %0,3 | 25 Şub 2025 |
26İzleyin | CVE-2025-63563İstismar yok | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password chsummerpearlgroup · vacation rental management platform · CWE-286 | Orta6,5 | — | %0,2 | 31 Eki 2025 |
25İzleyin | CVE-2024-9312İstismar yok | Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions.canonical · authd · CWE-286 | Orta6,4 | — | %0,3 | 10 Eki 2024 |
23İzleyin | CVE-2021-26262İstismar yok | Philips MRI 1.5T and 3T Improper Access Controlphilips · mri 3t firmware · CWE-286 | Orta5,9 | — | %0,7 | 19 Kas 2021 |
22İzleyin | CVE-2023-20253İstismar yok | A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attackecisco · catalyst sd-wan manager · CWE-286 | Orta5,5 | — | %0,2 | 27 Eyl 2023 |
21İzleyin | CVE-2024-29296Kavram kanıtı | A user enumeration vulnerability was found in Portainer CE 2.19.4.portainer · portainer · CWE-286 | Orta5,3 | — | %1,3 | 10 Nis 2024 |
21İzleyin | CVE-2023-3914İstismar yok | Incorrect User Management in GitLabgitlab · gitlab · CWE-286 | Orta5,3 | — | %0,4 | 29 Eyl 2023 |
- CVE-2022-3226039İzleyin
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).
KritikCVSS 9,8İstismar yokEPSS %1siemens · sinema remote connect server14 Haz 2022
- CVE-2023-2668939İzleyin
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
KritikCVSS 9,8İstismar yokEPSS %1cs-cart · cs-cart multivendor24 Eyl 2024
- CVE-2024-4885338İzleyin
Authenticated Escalation to guest to root
KritikCVSS 9,5İstismar yokEPSS %0abb · aspect-enterprise22 May 2025
- CVE-2023-390735İzleyin
Improper User Management in GitLab
YüksekCVSS 8,8İstismar yokEPSS %1gitlab · gitlab17 Ara 2023
- CVE-2024-5235935İzleyin
IBM Concert Software improper access controls
YüksekCVSS 8,8İstismar yokEPSS %0ibm · concert19 Kas 2024
- CVE-2021-2155335İzleyin
Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow
YüksekCVSS 8,8İstismar yokEPSS %0dell · powerscale onefs2 Ağu 2021
- CVE-2026-3563834İzleyin
OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI
YüksekCVSS 8,7İstismar yokEPSS %1openclaw · openclaw9 Nis 2026
- CVE-2025-797233İzleyin
Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability
YüksekCVSS 8,4İstismar yokEPSS %1rockwellautomation · factorytalk linx14 Ağu 2025
- CVE-2026-5642832İzleyin
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default con
YüksekCVSS 8,1İstismar yokEPSS %0bosch · bsh elp (electronic platform) modules30 Tem 2026
- CVE-2024-2802032İzleyin
A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management.
YüksekCVSS 8,0İstismar yokEPSS %0hitachienergy · foxman-un11 Haz 2024
- CVE-2023-2551931İzleyin
NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrec
YüksekCVSS 7,8İstismar yokEPSS %0nvidia · bluefield 1 firmware11 Eyl 2023
- CVE-2024-5810531İzleyin
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing s
YüksekCVSS 7,8İstismar yokEPSS %0trendmicro · apex one25 Mar 2025
- CVE-2023-085730İzleyin
Unintentional change of settings during initial registration of system administrators which uses control protocols.
YüksekCVSS 7,5İstismar yokEPSS %1canon · mf642cdw firmware11 May 2023
- CVE-2022-4585730İzleyin
An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attack
YüksekCVSS 7,5İstismar yokEPSS %0fortinet · fortimanager5 Oca 2023
- CVE-2024-4667128İzleyin
An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below,
YüksekCVSS 7,2Kavram kanıtıEPSS %0fortinet · fortiweb8 Nis 2025
- CVE-2026-6013528İzleyin
Weintek cMT3092X Incorrect User Management
YüksekCVSS 7,1İstismar yokEPSS %0weintek · cmt3092x firmware24 Tem 2026
- CVE-2024-2726927İzleyin
IBM QRadar SIEM information disclosure
OrtaCVSS 6,8İstismar yokEPSS %0ibm · qradar security information and event manager14 May 2024
- CVE-2023-393226İzleyin
Incorrect User Management in GitLab
OrtaCVSS 6,5İstismar yokEPSS %1gitlab · gitlab3 Ağu 2023
- CVE-2024-4542526İzleyin
Zoom Workplace Apps - Incorrect User Management
OrtaCVSS 6,5İstismar yokEPSS %0zoom · meeting software development kit25 Şub 2025
- CVE-2025-6356326İzleyin
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password ch
OrtaCVSS 6,5İstismar yokEPSS %0summerpearlgroup · vacation rental management platform31 Eki 2025
- CVE-2024-931225İzleyin
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions.
OrtaCVSS 6,4İstismar yokEPSS %0canonical · authd10 Eki 2024
- CVE-2021-2626223İzleyin
Philips MRI 1.5T and 3T Improper Access Control
OrtaCVSS 5,9İstismar yokEPSS %1philips · mri 3t firmware19 Kas 2021
- CVE-2023-2025322İzleyin
A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacke
OrtaCVSS 5,5İstismar yokEPSS %0cisco · catalyst sd-wan manager27 Eyl 2023
- CVE-2024-2929621İzleyin
A user enumeration vulnerability was found in Portainer CE 2.19.4.
OrtaCVSS 5,3Kavram kanıtıEPSS %1portainer · portainer10 Nis 2024
- CVE-2023-391421İzleyin
Incorrect User Management in GitLab
OrtaCVSS 5,3İstismar yokEPSS %0gitlab · gitlab29 Eyl 2023