Vulnerabilities (CVE)

Filtered by CWE-862
Total 9920 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36506 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in YITH YITH WooCommerce Waiting List allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Waiting List: from n/a through 2.13.0.
CVE-2023-36504 1 Bbsetheme 1 Bbs E-popup 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5.
CVE-2023-36348 1 Codekop 1 Codekop 2026-06-17 N/A 8.8 HIGH
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
CVE-2023-36140 1 Phpjabbers 1 Cleaning Business Software 2026-06-17 N/A 9.8 CRITICAL
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
CVE-2023-36002 1 Proofpoint 1 Insider Threat Management Server 2026-06-17 N/A 4.3 MEDIUM
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.
CVE-2023-36000 2 Apple, Proofpoint 2 Macos, Insider Threat Management Server 2026-06-17 N/A 6.5 MEDIUM
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.
CVE-2023-35998 1 Proofpoint 1 Insider Threat Management Server 2026-06-17 N/A 4.6 MEDIUM
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.
CVE-2023-35940 1 Glpi-project 1 Glpi 2026-06-17 N/A 7.5 HIGH
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contains a patch for this issue.
CVE-2023-35937 1 Metersphere 1 Metersphere 2026-06-17 N/A 6.0 MEDIUM
Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere lack permission checks. This allows ordinary users to execute APIs that can only be executed by space administrators or project administrators. For example, ordinary users can be updated as space administrators. Version 2.10.2 LTS has a patch for this issue.
CVE-2023-35875 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Jegstudio Gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through 1.8.5.
CVE-2023-35777 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2.
CVE-2023-35677 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In onCreate of DeviceAdminAdd.java, there is a possible way to forcibly add a device admin due to a missing permission check. This could lead to local denial of service (factory reset or continuous locking) with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-35665 1 Google 1 Android 2026-06-17 N/A 7.8 HIGH
In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-35164 1 Dataease 1 Dataease 2026-06-17 N/A 6.3 MEDIUM
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2023-35149 1 Jenkins 1 Digital.ai App Management Publisher 2026-06-17 N/A 6.5 MEDIUM
A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.
CVE-2023-35093 1 Stylemixthemes 1 Masterstudy Lms 2026-06-17 N/A 6.5 MEDIUM
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.
CVE-2023-35052 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in wpWax - WP Business Directory Plugin and Classified Listings Directory Directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through 7.5.4.
CVE-2023-35051 1 Cimatti 1 Wordpress Contact Forms 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Forms by Cimatti: from n/a through 1.5.7.
CVE-2023-35050 2026-06-17 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0.
CVE-2023-35049 1 Woocommerce 1 Stripe Payment Gateway 2026-06-17 N/A 7.5 HIGH
Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.