CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,303 vulnerabilities with CWE-284
CVE-2023-29164 HIGH
Intel Server Board - Privilege Escalation
CVSS 7.3
CVE-2023-52164 MEDIUM
Digiever DS-2105 Pro <3.1.0.71-11 - Info Disclosure
CVSS 5.1
CVE-2023-51644 HIGH
Allegra < 7.5.1 - Unauthenticated Remote Code Execution via Struts Improper Access Control
CVSS 7.3
CVE-2023-29121 CRITICAL
Waybox Enel TCF Agent - Privilege Escalation
CVSS 9.6
CVE-2023-29115 MEDIUM
Enel X Waybox Pro Firmware < 2.1.1.0_jb3vu096a - Denial of Service
CVSS 6.5
CVE-2023-26770 CRITICAL
TaskCafe 0.3.2 - Unauthenticated Password Change via Cookie Manipulation
CVSS 9.8
CVE-2023-43626 HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.5
CVE-2023-37234 CRITICAL
Loftware Spectrum < 4.6 - Unauthenticated Improper Access Control via JMX Registry
CVSS 9.8
CVE-2023-30587 HIGH
Node.js < 20.3.1 - Permission Model Bypass via Inspector Worker Manipulation
CVSS 7.5
CVE-2023-30583 HIGH
Node.js < 20.3.1 - Permission Model Bypass via fs.openAsBlob()
CVSS 7.5
CVE-2023-30582 MEDIUM
Node.js 20 < 20.3.1 - Unauthorized File Monitoring via fs.watchFile API
CVSS 5.3
CVE-2023-43489 MEDIUM
Intel Computing Improvement Program < 2.4.10717 - Authenticated Denial of Service via Local Access
CVSS 5.5
CVE-2023-31341 HIGH
AMD Prof < 4.1.424, < 4.2.816, < 4.2.845 - Authenticated Denial of Service via IOCTL Input Buffer
CVSS 7.3
CVE-2023-42957 LOW
iPadOS < 17.0 - Unauthorized Sensitive Location Information Access
CVSS 3.3
CVE-2023-50181 MEDIUM
FortiADC 7.4.0-7.4.1 and < 7.2.4 - Authenticated Improper Access Control via HTTP/HTTPS Requests
CVSS 4.9
CVE-2023-6491 MEDIUM
Strong Testimonials <3.1.12 - Info Disclosure
CVSS 4.3
CVE-2023-6968 HIGH
The Moneytizer < 9.6.3 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 8.1
CVE-2023-6966 HIGH
The Moneytizer <= 9.6.3 - Authenticated Improper Access Control in core_ajax.php
CVSS 8.1
CVE-2023-43849 MEDIUM
Aten PE6208 Firmware 2.3.228-2.4.232 - Authenticated Arbitrary Firmware Upload via Web Interface
CVSS 6.5
CVE-2023-43848 HIGH
Aten PE6208 <2.4.232 - Privilege Escalation
CVSS 8.0
CVE-2023-43847 MEDIUM
Aten PE6208 <2.4.232 - Privilege Escalation
CVSS 5.3
CVE-2023-52712 HIGH
Huawei Curiem-WFG9B Firmware - Improper Access Control via Exposed SMI Handler
CVSS 7.8
CVE-2023-52711 HIGH
Huawei Curiem-WFG9B Firmware - Improper Access Control via Exposed SMI Handler
CVSS 7.8
CVE-2023-52801 CRITICAL
Linux Kernel - Use-After-Free in iommufd iopt_area_split
CVSS 9.1
CVE-2023-47859 MEDIUM
Intel(R) Wireless Bluetooth <23.20 - DoS
CVSS 5.5
Details
Vulnerabilities 5,303