Vulnerabilities (CVE)

Filtered by CWE-285
Total 1610 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-22177 1 Atlassian 1 Jira Align 2026-06-17 N/A 4.3 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.
CVE-2025-22176 1 Atlassian 1 Jira Align 2026-06-17 N/A 4.3 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.
CVE-2025-22175 1 Atlassian 1 Jira Align 2026-06-17 N/A 5.4 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
CVE-2025-22174 1 Atlassian 1 Jira Align 2026-06-17 N/A 4.3 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
CVE-2025-22173 1 Atlassian 1 Jira Align 2026-06-17 N/A 4.3 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.
CVE-2025-22172 1 Atlassian 1 Jira Align 2026-06-17 N/A 4.3 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.
CVE-2025-22171 1 Atlassian 1 Jira Align 2026-06-17 N/A 4.3 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
CVE-2025-22170 1 Atlassian 1 Jira Align 2026-06-17 N/A 4.3 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.
CVE-2025-22169 1 Atlassian 1 Jira Align 2026-06-17 N/A 5.4 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.
CVE-2025-22168 1 Atlassian 1 Jira Align 2026-06-17 N/A 4.3 MEDIUM
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.
CVE-2025-21611 1 Tgstation13 1 Tgstation-server 2026-06-17 N/A 8.8 HIGH
tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role used to determine if a user was enabled. This allows enabled users access to most, but not all, authorized actions regardless of their permissions. Notably, the WriteUsers right is unaffected so users may not use this bug to permanently elevate their account permissions. The fix is release in tgstation-server-v6.12.3.
CVE-2025-21400 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 8.0 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2025-21348 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 7.2 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2025-21275 1 Microsoft 8 Windows 10 21h2, Windows 10 22h2, Windows 11 22h2 and 5 more 2026-06-17 N/A 7.8 HIGH
Windows App Package Installer Elevation of Privilege Vulnerability
CVE-2025-20264 1 Cisco 1 Identity Services Engine 2026-06-17 N/A 6.4 MEDIUM
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to insufficient authorization enforcement mechanisms for users created by SAML SSO integration with an external identity provider. An attacker could exploit this vulnerability by submitting a series of specific commands to an affected device. A successful exploit could allow the attacker to modify a limited number of system settings, including some that would result in a system restart. In single-node Cisco ISE deployments, devices that are not authenticated to the network will not be able to authenticate until the Cisco ISE system comes back online. 
CVE-2025-20125 1 Cisco 1 Identity Services Engine 2026-06-17 N/A 9.1 CRITICAL
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to attacker to obtain information, modify system configuration, and reload the device. Note: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.
CVE-2025-1847 1 Zframeworks 1 Zz 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-1815 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The manipulation of the argument user_cookie leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-1806 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
A vulnerability, which was classified as problematic, has been found in Eastnets PaymentSafe 2.5.26.0. Affected by this issue is some unknown functionality of the file /Default.aspx of the component URL Handler. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.5.27.0 is able to address this issue.
CVE-2025-1607 1 Mayurik 1 Best Employee Management System 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Employee Management System 1.0. This issue affects some unknown processing of the file /admin/salary_slip.php. The manipulation of the argument id leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.