Vulnerabilities (CVE)

Filtered by CWE-862
Total 9920 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38439 2 Google, Unisoc 8 Android, Sc9832e, Sc9863a and 5 more 2026-06-17 N/A 5.5 MEDIUM
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVE-2023-38438 2 Google, Unisoc 9 Android, Sc7731e, Sc9832e and 6 more 2026-06-17 N/A 5.5 MEDIUM
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVE-2023-38437 2 Google, Unisoc 9 Android, Sc7731e, Sc9832e and 6 more 2026-06-17 N/A 5.5 MEDIUM
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVE-2023-38436 2 Google, Unisoc 9 Android, Sc7731e, Sc9832e and 6 more 2026-06-17 N/A 5.5 MEDIUM
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
CVE-2023-38395 1 Afzalmultani 1 Wp Clone Menu 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.
CVE-2023-38394 1 Artbees 1 Jupiter X Core 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.
CVE-2023-38393 1 Ninjaforms 1 Ninja Forms 2026-06-17 N/A 7.6 HIGH
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
CVE-2023-38386 1 Ninjaforms 1 Ninja Forms 2026-06-17 N/A 7.6 HIGH
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
CVE-2023-38385 1 Artbees 1 Jupiter X Core 2026-06-17 N/A 8.3 HIGH
Missing Authorization vulnerability in Artbees JupiterX Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.
CVE-2023-38383 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in OnTheGoSystems Language allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Language: from n/a through 1.2.1.
CVE-2023-38102 1 Netgear 1 Prosafe Network Management System 2026-06-17 N/A 8.8 HIGH
NETGEAR ProSAFE Network Management System createUser Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the createUser function. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the user. Was ZDI-CAN-19726.
CVE-2023-37989 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Easyship Easyship WooCommerce Shipping Rates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easyship WooCommerce Shipping Rates: from n/a through 0.9.0.
CVE-2023-37987 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in miniOrange YourMembership Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YourMembership Single Sign On: from n/a through 1.1.3.
CVE-2023-37984 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in ExpressTech Quiz And Survey Master allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through 8.1.10.
CVE-2023-37971 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Product Stock Alert: from n/a through 2.0.1.
CVE-2023-37969 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in The African Boss Checkout with Zelle on Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout with Zelle on Woocommerce: from n/a through 3.1.
CVE-2023-37967 1 Designinvento 1 Directorypress 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in Designinvento DirectoryPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through 3.6.2.
CVE-2023-37965 1 Jenkins 1 Elasticbox Ci 2026-06-17 N/A 7.1 HIGH
A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2023-37963 1 Jenkins 1 Benchmark Evaluator 2026-06-17 N/A 5.4 MEDIUM
A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system.
CVE-2023-37959 1 Jenkins 1 Sumologic Publisher 2026-06-17 N/A 6.5 MEDIUM
A missing permission check in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.