Vulnerabilities (CVE)

Filtered by CWE-345
Total 771 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36541 1 Zoom 1 Zoom 2026-06-17 N/A 8.0 HIGH
Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via network access.
CVE-2023-36139 1 Phpjabbers 1 Cleaning Business Software 2026-06-17 N/A 9.8 CRITICAL
In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
CVE-2023-36134 1 Phpjabbers 1 Class Scheduling System 2026-06-17 N/A 9.8 CRITICAL
In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
CVE-2023-35906 2 Ibm, Linux 2 Aspera Faspex, Linux Kernel 2026-06-17 N/A 5.3 MEDIUM
IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649.
CVE-2023-35764 1 Ays-pro 1 Survey Maker 2026-06-17 N/A 5.3 MEDIUM
Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.
CVE-2023-35719 1 Zohocorp 1 Manageengine Adselfservice Plus 2026-06-17 N/A 6.8 MEDIUM
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Password Reset Portal used by the GINA client. The issue results from the lack of proper authentication of data received via HTTP. An attacker can leverage this vulnerability to bypass authentication and execute code in the context of SYSTEM. Was ZDI-CAN-17009.
CVE-2023-32993 1 Jenkins 1 Saml Single Sign On 2026-06-17 N/A 4.8 MEDIUM
Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.
CVE-2023-32329 1 Ibm 2 Security Verify Access, Security Verify Access Docker 2026-06-17 N/A 6.2 MEDIUM
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972.
CVE-2023-31502 1 Apsystems 3 Alternergy Power Control Software, Ecu-c, Ecu-r 2026-06-17 N/A 7.2 HIGH
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php.
CVE-2023-30759 1 Ricoh 1 Printer Driver Packager Nx 2026-06-17 N/A 7.8 HIGH
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an unexpected process with the administrative privilege. If a non-administrative user modifies the driver installation package and runs it on the target PC, an arbitrary program may be executed with the administrative privilege.
CVE-2023-30562 1 Bd 1 Alaris Guardrails Editor 2026-06-17 N/A 6.7 MEDIUM
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
CVE-2023-30559 1 Bd 2 Alaris 8015 Pcu, Alaris 8015 Pcu Firmware 2026-06-17 N/A 5.2 MEDIUM
The firmware update package for the wireless card is not properly signed and can be modified.
CVE-2023-2987 1 Wordapp 1 Wordapp 2026-06-17 N/A 9.8 CRITICAL
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to the plugin to change the 'validation_token' in the plugin config, providing access to the plugin's remote control functionalities, such as creating an admin access URL, which can be used for privilege escalation.
CVE-2023-2897 1 Brizy 1 Brizy 2026-06-17 N/A 3.7 LOW
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwarded-For' HTTP header for the purpose of validating allowed IP addresses against a Maintenance Mode whitelist. Supplying a whitelisted IP address within the 'X-Forwarded-For' header allows maintenance mode to be bypassed and may result in the disclosure of potentially sensitive information or allow access to restricted functionality.
CVE-2023-2866 1 Advantech 1 Webaccess 2026-06-17 N/A 7.3 HIGH
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.
CVE-2023-2314 1 Google 1 Chrome 2026-06-17 N/A 6.5 MEDIUM
Insufficient data validation in DevTools in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-28865 1 Dieboldnixdorf 1 Vynamic Security Suite 2026-06-17 N/A 6.6 MEDIUM
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected hash sum) during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk.
CVE-2023-28863 1 Ami 1 Megarac Sp-x 2026-06-17 N/A 9.1 CRITICAL
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
CVE-2023-28457 1 Technitium 1 Dnsserver 2026-06-17 N/A 7.5 HIGH
An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and inject fake responses within 1 second, which is impactful.
CVE-2023-28386 2 Control4, Snapone 13 Ca-1, Ca-10, Ea-1 and 10 more 2026-06-17 N/A 8.6 HIGH
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a private-public key mechanism. The lack of complete PKI system firmware signature could allow attackers to upload arbitrary firmware updates, resulting in code execution.