CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,303 vulnerabilities with CWE-284
CVE-2023-32544 HIGH
Intel NUC P14E Laptop Element < 1.1.45 - Authenticated Denial of Service via HotKey Services Installer
CVSS 7.3
CVE-2023-47034 HIGH
UniswapFrontRunBot - Improper Access Control
CVSS 7.5
CVE-2023-20260 MEDIUM
Cisco Prime Infrastructure - Privilege Escalation
CVSS 6.0
CVE-2023-21901 HIGH
Oracle Financial Services Analytical Apps <8.1.2 - RCE
CVSS 7.4
CVE-2023-52105 HIGH
Huawei HarmonyOS - Privilege Escalation
CVSS 7.5
CVE-2023-52099 HIGH
Huawei EMUI and HarmonyOS - Improper Access Control in NMS Module
CVSS 7.5
CVE-2023-52114 HIGH
Huawei EMUI and HarmonyOS - Data Confidentiality Vulnerability in ScreenReader Module
CVSS 7.5
CVE-2023-51070 HIGH
QStar Archive Solutions <RELEASE_3-0 Build 7 Patch 0 - Info Disclosure
CVSS 7.5
CVE-2023-51065 HIGH
QStar Archive Solutions <RELEASE_3-0 Build 7 Patch 0 - Info Disclosure
CVSS 7.5
CVE-2023-49099 LOW
Discourse < 3.1.4 - Unauthenticated Secure Upload URL Access
CVSS 3.1
CVE-2023-49098 LOW
Discourse-reactions - Info Disclosure
CVSS 3.5
CVE-2023-51751 MEDIUM
ScaleFusion 10.5.2 - Info Disclosure
CVSS 6.8
CVE-2023-50159 HIGH
ScaleFusion 10.5.2 - Kiosk Mode Bypass via File Explorer Launch
CVSS 8.8
CVE-2023-6582 MEDIUM
ElementsKit Elementor addons <3.0.3 - Info Disclosure
CVSS 5.3
CVE-2023-28197 LOW
macOS < 11.7.5 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 3.3
CVE-2023-46712 HIGH
Fortinet FortiPortal <7.0.6, <7.2.1 - Privilege Escalation
CVSS 7.2
CVE-2023-41603 MEDIUM
D-Link R15 <v1.08.02 - Info Disclosure
CVSS 5.3
CVE-2023-7223 MEDIUM
Totolink T6 4.1.9cu.5241_B20210923 - Improper Access Control via cstecgi.cgi topicurl Parameter
CVSS 5.3
CVE-2023-49961 HIGH
WALLIX Bastion 7.x-10.x and Access Manager 3.x-4.x - Improper Access Control
CVSS 7.5
CVE-2023-29051 HIGH
OX App Suite < 7.10.6 - Unauthenticated Improper Access Control via User-Defined OXMF Templates
CVSS 8.1
CVE-2023-6733 MEDIUM
WP-Members Membership Plugin <= 3.4.8 - Authenticated Sensitive Information Exposure via wpmem_field Shortcode
CVSS 6.5
CVE-2023-50344 MEDIUM
HCL DRYiCE MyXalytics - Unauthenticated File Download via Improper Access Control
CVSS 5.4
CVE-2023-50343 HIGH
HCL DRYiCE MyXalytics - Authenticated Improper Access Control via Controller APIs
CVSS 8.3
CVE-2023-50341 HIGH
HCL DRYiCE MyXalytics - Improper Access Control via Obsolete Web Pages
CVSS 7.6
CVE-2023-50333 LOW
Mattermost < 8.1.7 - Improper Access Control via Session Permission Update
CVSS 3.7
Details
Vulnerabilities 5,303