Search Results (7741 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-46823 2025-05-30 N/A
openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In versions of the FHIR2 module prior to 2.5.0, privileges were not always correctly checked, which means that unauthorized users may have been able to add or edit data they were not supposed to be able to. All implementers should update to FHIR2 2.5.0 or newer as soon as is feasible to receive a patch.
CVE-2023-43846 1 Aten 2 Pe6208, Pe6208 Firmware 2025-05-30 5.3 Medium
Incorrect access control in logs management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote attackers to get the device logs via HTTP GET request. The logs contain such information as user names and IP addresses used in the infrastructure. This information may help the attackers to conduct further attacks in the infrastructure.
CVE-2018-10207 1 Vaultize 1 Enterprise File Sharing 2025-05-30 N/A
An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. An attacker can exploit Missing Authorization on the FlexPaperViewer SWF reader, and export files that should have been restricted, via vectors involving page-by-page access to a document in SWF format.
CVE-2024-23752 1 Gabrieleventuri 1 Pandasai 2025-05-30 9.8 Critical
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor previously attempted to restrict code execution in response to a separate issue, CVE-2023-39660.
CVE-2024-32715 1 Olivethemes 1 Olive One Click Demo Import 2025-05-29 5.3 Medium
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
CVE-2022-41238 1 Jenkins 1 Dotci 2025-05-29 9.8 Critical
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.
CVE-2024-21630 1 Zulip 1 Zulip Server 2025-05-29 4.3 Medium
Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links as in the prior CVE. Specifically, it applies when the installation has configured non-admins to be able to invite users and create multi-use invitations, and has also configured only admins to be able to invite users to streams. As in CVE-2023-32677, this does not let users invite new users to arbitrary streams, only to streams that the inviter can already see. Version 8.1 fixes this issue. As a workaround, administrators can limit sending of invitations down to users who also have the permission to add users to streams.
CVE-2023-42706 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 5.5 Medium
In firewall service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42698 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 5.5 Medium
In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed
CVE-2023-42685 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 7.8 High
In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42681 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 7.8 High
In ion service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-1705 1 Forcepoint 1 One Smartedge Agent 2025-05-29 8.4 High
Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Functionality Bypass.This issue affects F|One SmartEdge Agent: before 1.7.0.230330-554.
CVE-2023-42747 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 7.8 High
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2023-42736 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-05-29 7.8 High
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
CVE-2024-31099 1 Averta 1 Shortcodes And Extra Features For Phlox Theme 2025-05-29 6.4 Medium
Missing Authorization vulnerability in Averta Shortcodes and extra features for Phlox theme auxin-elements.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.7.
CVE-2024-39635 1 Kainelabs 1 Youzify 2025-05-28 5.4 Medium
Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youzify: from n/a through 1.2.6.
CVE-2025-1813 1 Zframeworks 1 Zz 2025-05-28 4.3 Medium
A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2022-41228 1 Jenkins 1 Ns-nd Integration Performance Publisher 2025-05-28 8.8 High
A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.
CVE-2025-28103 1 Dogukanurker 1 Flaskblog 2025-05-28 6.4 Medium
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
CVE-2022-41254 1 Jenkins 1 Cons3rt 2025-05-28 6.5 Medium
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.