İçeriğe atla
Noroxi

CWE-286 · 30 kayıt

Incorrect User Management

Bu sınıftaki CVE’ler

30 kayıt

  • CVE-2022-32260
    39İzleyin

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).

    KritikCVSS 9,8İstismar yokEPSS %1

    siemens · sinema remote connect server14 Haz 2022

  • CVE-2023-26689
    39İzleyin

    An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

    KritikCVSS 9,8İstismar yokEPSS %1

    cs-cart · cs-cart multivendor24 Eyl 2024

  • CVE-2024-48853
    38İzleyin

    Authenticated Escalation to guest to root

    KritikCVSS 9,5İstismar yokEPSS %0

    abb · aspect-enterprise22 May 2025

  • CVE-2023-3907
    35İzleyin

    Improper User Management in GitLab

    YüksekCVSS 8,8İstismar yokEPSS %1

    gitlab · gitlab17 Ara 2023

  • CVE-2024-52359
    35İzleyin

    IBM Concert Software improper access controls

    YüksekCVSS 8,8İstismar yokEPSS %0

    ibm · concert19 Kas 2024

  • CVE-2021-21553
    35İzleyin

    Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow

    YüksekCVSS 8,8İstismar yokEPSS %0

    dell · powerscale onefs2 Ağu 2021

  • CVE-2026-35638
    34İzleyin

    OpenClaw < 2026.3.22 - Privilege Escalation via Self-Declared Scopes in Trusted-Proxy Control UI

    YüksekCVSS 8,7İstismar yokEPSS %1

    openclaw · openclaw9 Nis 2026

  • CVE-2025-7972
    33İzleyin

    Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability

    YüksekCVSS 8,4İstismar yokEPSS %1

    rockwellautomation · factorytalk linx14 Ağu 2025

  • CVE-2026-56428
    32İzleyin

    The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default con

    YüksekCVSS 8,1İstismar yokEPSS %0

    bosch · bsh elp (electronic platform) modules30 Tem 2026

  • CVE-2024-28020
    32İzleyin

    A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management.

    YüksekCVSS 8,0İstismar yokEPSS %0

    hitachienergy · foxman-un11 Haz 2024

  • CVE-2023-25519
    31İzleyin

    NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrec

    YüksekCVSS 7,8İstismar yokEPSS %0

    nvidia · bluefield 1 firmware11 Eyl 2023

  • CVE-2024-58105
    31İzleyin

    A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing s

    YüksekCVSS 7,8İstismar yokEPSS %0

    trendmicro · apex one25 Mar 2025

  • CVE-2023-0857
    30İzleyin

    Unintentional change of settings during initial registration of system administrators which uses control protocols.

    YüksekCVSS 7,5İstismar yokEPSS %1

    canon · mf642cdw firmware11 May 2023

  • CVE-2022-45857
    30İzleyin

    An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attack

    YüksekCVSS 7,5İstismar yokEPSS %0

    fortinet · fortimanager5 Oca 2023

  • CVE-2024-46671
    28İzleyin

    An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below,

    YüksekCVSS 7,2Kavram kanıtıEPSS %0

    fortinet · fortiweb8 Nis 2025

  • CVE-2026-60135
    28İzleyin

    Weintek cMT3092X Incorrect User Management

    YüksekCVSS 7,1İstismar yokEPSS %0

    weintek · cmt3092x firmware24 Tem 2026

  • CVE-2024-27269
    27İzleyin

    IBM QRadar SIEM information disclosure

    OrtaCVSS 6,8İstismar yokEPSS %0

    ibm · qradar security information and event manager14 May 2024

  • CVE-2023-3932
    26İzleyin

    Incorrect User Management in GitLab

    OrtaCVSS 6,5İstismar yokEPSS %1

    gitlab · gitlab3 Ağu 2023

  • CVE-2024-45425
    26İzleyin

    Zoom Workplace Apps - Incorrect User Management

    OrtaCVSS 6,5İstismar yokEPSS %0

    zoom · meeting software development kit25 Şub 2025

  • CVE-2025-63563
    26İzleyin

    Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password ch

    OrtaCVSS 6,5İstismar yokEPSS %0

    summerpearlgroup · vacation rental management platform31 Eki 2025

  • CVE-2024-9312
    25İzleyin

    Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions.

    OrtaCVSS 6,4İstismar yokEPSS %0

    canonical · authd10 Eki 2024

  • CVE-2021-26262
    23İzleyin

    Philips MRI 1.5T and 3T Improper Access Control

    OrtaCVSS 5,9İstismar yokEPSS %1

    philips · mri 3t firmware19 Kas 2021

  • CVE-2023-20253
    22İzleyin

    A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacke

    OrtaCVSS 5,5İstismar yokEPSS %0

    cisco · catalyst sd-wan manager27 Eyl 2023

  • CVE-2024-29296
    21İzleyin

    A user enumeration vulnerability was found in Portainer CE 2.19.4.

    OrtaCVSS 5,3Kavram kanıtıEPSS %1

    portainer · portainer10 Nis 2024

  • CVE-2023-3914
    21İzleyin

    Incorrect User Management in GitLab

    OrtaCVSS 5,3İstismar yokEPSS %0

    gitlab · gitlab29 Eyl 2023

Tüm zafiyet sınıfları