Filtered by CWE-286
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-9312 1 Ubuntu 1 Authd 2024-10-15 7.5 High
Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain their privileges.
CVE-2023-26689 1 Cs-cart 1 Cs-cart Multivendor 2024-09-26 9.8 Critical
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.