HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fix…
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check …
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check …
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional executi…
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed.
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges ne…
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.
metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/downl…
The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to m…
The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free…
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and inclu…
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in …
Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.10…
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team…
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks…