Vulnerabilities (CVE)

Filtered by CWE-863
Total 2327 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0577 2 Debian, Scrapy 2 Debian Linux, Scrapy 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
CVE-2022-0574 1 Publify Project 1 Publify 2024-11-21 6.4 MEDIUM 6.5 MEDIUM
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
CVE-2022-0482 1 Easyappointments 1 Easyappointments 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.
CVE-2022-0451 1 Dart 1 Dart Software Development Kit 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to example.com with authorization header and it redirects to an attackers site, they might not expect attacker site to receive authorization header. We recommend updating the Dart SDK to version 2.16.0 or beyond.
CVE-2022-0406 1 Janeczku 1 Calibre-web 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
CVE-2022-0334 1 Moodle 1 Moodle 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view capability.
CVE-2022-0333 1 Moodle 1 Moodle 2024-11-21 5.5 MEDIUM 3.8 LOW
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.
CVE-2022-0309 1 Google 1 Chrome 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
CVE-2022-0273 1 Janeczku 1 Calibre-web 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Improper Access Control in Pypi calibreweb prior to 0.6.16.
CVE-2022-0143 1 Forgerock 1 Ldap Connector 2024-11-21 N/A 9.3 CRITICAL
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)
CVE-2022-0117 2 Fedoraproject, Google 2 Fedora, Chrome 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
CVE-2021-4352 1 Eyecix 1 Jobsearch Wp Job Board 2024-11-21 N/A 5.3 MEDIUM
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated attackers to change the settings of the plugin.
CVE-2021-4334 1 Radykal 1 Fancy Product Designer 2024-11-21 N/A 8.8 HIGH
The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with subscriber-level permissions to modify site options, including setting the default role to administrator which can allow privilege escalation.
CVE-2021-4275 1 Pyambic-pentameter Project 1 Pyambic-pentameter 2024-11-21 N/A 4.3 MEDIUM
A vulnerability, which was classified as problematic, was found in katlings pyambic-pentameter. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The name of the patch is 974f21aa1b2527ef39c8afe1a5060548217deca8. It is recommended to apply a patch to fix this issue. VDB-216498 is the identifier assigned to this vulnerability.
CVE-2021-4268 1 Phpredisadmin Project 1 Phpredisadmin 2024-11-21 N/A 4.3 MEDIUM
A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.18.0 is able to address this issue. The name of the patch is b9039adbb264c81333328faa9575ecf8e0d2be94. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216471.
CVE-2021-4194 1 Bookstackapp 1 Bookstack 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
bookstack is vulnerable to Improper Access Control
CVE-2021-4133 1 Redhat 1 Keycloak 2024-11-21 6.5 MEDIUM 8.8 HIGH
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
CVE-2021-4026 1 Bookstackapp 1 Bookstack 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
bookstack is vulnerable to Improper Access Control
CVE-2021-46891 1 Huawei 2 Emui, Harmonyos 2024-11-21 N/A 9.8 CRITICAL
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
CVE-2021-46890 1 Huawei 2 Emui, Harmonyos 2024-11-21 N/A 9.8 CRITICAL
Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.