Vulnerabilities (CVE)

Filtered by CWE-284
Total 7821 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1553 1 Publify Project 1 Publify 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.
CVE-2022-1521 1 Illumina 8 Iseq 100, Local Run Manager, Miniseq and 5 more 2026-06-17 6.4 MEDIUM 9.1 CRITICAL
LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.
CVE-2022-1261 1 Honeywell 1 Matrikon Opc Server 2026-06-17 9.0 HIGH 5.8 MEDIUM
Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to the OPC server to use the functions of the IPersisFile to execute operating system processes with system-level privileges.
CVE-2022-1066 1 Aethon 1 Tug Home Base Server 2026-06-17 N/A 8.2 HIGH
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
CVE-2022-1025 1 Argoproj 1 Argo Cd 2026-06-17 9.0 HIGH 8.8 HIGH
All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
CVE-2022-0824 1 Webmin 1 Webmin 2026-06-17 9.0 HIGH 8.8 HIGH
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
CVE-2022-0732 1 1byte 9 Copy9, Exactspy, Fonetracker and 6 more 2026-06-17 5.0 MEDIUM 7.5 HIGH
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
CVE-2022-0731 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
CVE-2022-0727 1 Framasoft 1 Peertube 2026-06-17 5.5 MEDIUM 5.4 MEDIUM
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
CVE-2022-0574 1 Publify Project 1 Publify 2026-06-17 6.4 MEDIUM 6.5 MEDIUM
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
CVE-2022-0541 1 Flothemes 1 Flo-launch 2026-06-17 7.5 HIGH 9.8 CRITICAL
The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.
CVE-2022-0405 1 Janeczku 1 Calibre-web 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
CVE-2022-0273 1 Janeczku 1 Calibre-web 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Improper Access Control in Pypi calibreweb prior to 0.6.16.
CVE-2022-0270 1 Mirantis 1 Bored-agent 2026-06-17 6.5 MEDIUM 8.8 HIGH
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.
CVE-2022-0203 1 Craterapp 1 Crater 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.
CVE-2022-0170 1 Framasoft 1 Peertube 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
peertube is vulnerable to Improper Access Control
CVE-2022-0143 1 Forgerock 1 Ldap Connector 2026-06-17 N/A 9.3 CRITICAL
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)
CVE-2022-0133 1 Framasoft 1 Peertube 2026-06-17 5.0 MEDIUM 7.5 HIGH
peertube is vulnerable to Improper Access Control
CVE-2021-4380 1 Valvepress 1 Pinterest Automatic Pin 2026-06-17 N/A 9.8 CRITICAL
The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary options on a site that can be used to create new administrative user accounts or redirect unsuspecting site visitors.
CVE-2021-4364 1 Eyecix 1 Jobsearch Wp Job Board 2026-06-17 N/A 4.3 MEDIUM
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possible for authenticated attackers to add and/or modify schedule calls.