Vulnerabilities (CVE)

Filtered by CWE-284
Total 7905 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37478 1 Pnpm 1 Pnpm 2026-06-17 N/A 7.5 HIGH
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.
CVE-2023-37267 1 Umbraco 1 Umbraco Cms 2026-06-17 N/A 7.5 HIGH
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.
CVE-2023-37234 1 Loftware 1 Spectrum 2026-06-17 N/A 9.8 CRITICAL
Loftware Spectrum through 4.6 has unprotected JMX Registry.
CVE-2023-37194 1 Siemens 10 Simatic Cp 1604, Simatic Cp 1604 Firmware, Simatic Cp 1616 and 7 more 2026-06-17 N/A 6.7 MEDIUM
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). The kernel memory of affected devices is exposed to user-mode via direct memory access (DMA) which could allow a local attacker with administrative privileges to execute arbitrary code on the host system without any restrictions.
CVE-2023-36890 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 6.5 MEDIUM
Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2023-36820 1 Objectcomputing 1 Micronaut Security 2026-06-17 N/A 4.8 MEDIUM
Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same identity issuer/provider. Any OIDC setup using Micronaut where multiple OIDC applications exists for the same issuer but token auth are not meant to be shared. This issue has been patched in versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1.
CVE-2023-36790 1 Microsoft 1 Windows Server 2008 2026-06-17 N/A 7.8 HIGH
Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
CVE-2023-36725 1 Microsoft 7 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 4 more 2026-06-17 N/A 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-36722 1 Microsoft 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more 2026-06-17 N/A 4.4 MEDIUM
Active Directory Domain Services Information Disclosure Vulnerability
CVE-2023-36644 1 Itb-pim 1 Tradepro 2026-06-17 N/A 7.5 HIGH
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.
CVE-2023-36643 1 Itb-pim 1 Tradepro 2026-06-17 N/A 7.5 HIGH
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.
CVE-2023-36638 1 Fortinet 2 Fortianalyzer, Fortimanager 2026-06-17 N/A 4.3 MEDIUM
An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions API may allow a remote and authenticated API admin user to access some system settings such as the mail server settings through the API via a stolen GUI session ID.
CVE-2023-36635 1 Fortinet 1 Fortiswitchmanager 2026-06-17 N/A 7.1 HIGH
An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.
CVE-2023-36620 1 Nationaledtech 1 Boomerang 2026-06-17 N/A 4.6 MEDIUM
An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal memory of the app to a PC. This gives the user access to the API token that is used to authenticate requests to the API.
CVE-2023-36561 1 Microsoft 1 Azure Devops Server 2026-06-17 N/A 7.3 HIGH
Azure DevOps Server Elevation of Privilege Vulnerability
CVE-2023-36554 1 Fortinet 1 Fortimanager 2026-06-17 N/A 8.1 HIGH
A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.
CVE-2023-36465 1 Decidim 1 Decidim 2026-06-17 N/A 9.1 CRITICAL
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys. This issue has been patched in version 0.26.8 and 0.27.4.
CVE-2023-36404 1 Microsoft 11 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 8 more 2026-06-17 N/A 5.5 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVE-2023-36106 1 Powerjob 1 Powerjob 2026-06-17 N/A 7.5 HIGH
An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.
CVE-2023-35940 1 Glpi-project 1 Glpi 2026-06-17 N/A 7.5 HIGH
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.