CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-50343 HIGH
HCL DRYiCE MyXalytics - Authenticated Improper Access Control via Controller APIs
CVSS 8.3
CVE-2023-50341 HIGH
HCL DRYiCE MyXalytics - Improper Access Control via Obsolete Web Pages
CVSS 7.6
CVE-2023-50333 LOW
Mattermost < 8.1.7 - Improper Access Control via Session Permission Update
CVSS 3.7
CVE-2023-47858 MEDIUM
Mattermost < 8.1.7, < 7.8.10 - Improper Access Control via Archived Public Channel Endpoint
CVSS 4.3
CVE-2023-7193 MEDIUM
MTab Bookmark < 1.2.6 - Improper Access Control in Installation Component
CVSS 4.6
CVE-2023-50928 HIGH
awslabs_sandbox_accounts_for_events < 1.1.0 - Authenticated Improper Access Control via Non-Existent Event ID
CVSS 7.1
CVE-2023-49791 MEDIUM
Nextcloud Server 23.0.0-23.0.12.12, 26.0.0-26.0.8 - Improper Access Control via API Bypass
CVSS 5.4
CVE-2023-51661 HIGH
Wasmer <4.2.4 - Privilege Escalation
CVSS 8.4
CVE-2023-7055 MEDIUM
PHPGurukul Online Notes Sharing System 1.0 - Improper Access Control via Profile Mobile Number Parameter
CVSS 4.3
CVE-2023-50783 MEDIUM
Apache Airflow < 2.8.0 - Authenticated Unauthorized Variable Modification
CVSS 6.5
CVE-2023-7025 HIGH
KylinSoft hedron-domain-hook < 3.8.0.12-0k0.5 - Improper Access Control in DBus Handler
CVSS 7.8
CVE-2023-51390 MEDIUM
journalpump <2.5.0 - Info Disclosure
CVSS 6.5
CVE-2023-50706 MEDIUM
efacec UC_500E Firmware - Unauthenticated Sensitive Information Exposure via Memory Dump
CVSS 4.1
CVE-2023-6930 CRITICAL
EuroTel ETL3100 v01c01 and v01x37 - Unauthenticated Sensitive Information Disclosure via Configuration and Log Download
CVSS 9.4
CVE-2023-51384 MEDIUM
OpenSSH <9.6 - Privilege Escalation
CVSS 5.5
CVE-2023-48441 MEDIUM
Adobe Experience Manager <6.5.18 - Info Disclosure
CVSS 5.3
CVE-2023-21751 MEDIUM
Azure DevOps Server - Open Redirect
CVSS 6.5
CVE-2023-50440 MEDIUM
PRIMX ZED! ZEDMAIL ZONECENTRAL ZEDFREE ZEDPRO < 2023.5 - Unauthenticated Access Control Bypass via UNC Injection
CVSS 5.5
CVE-2023-6773 MEDIUM
CodeAstro POS and Inventory Management System 1.0 - Improper Access Control via User Creation Handler
CVSS 4.3
CVE-2023-6761 MEDIUM
IceCMS <= 2.0.1 - Improper Access Control in User Data Handler
CVSS 4.3
CVE-2023-6758 MEDIUM
Thecosy IceCMS 2.0.1 - Improper Access Control in PlanetCommentList API
CVSS 5.3
CVE-2023-47325 MEDIUM
Silverpeas < 6.3.2 - Broken Access Control in Administrative Bin Feature
CVSS 5.4
CVE-2023-47536 LOW
FortiOS/FortiProxy Unauthenticated Firewall Policy Bypass via GeoIP Update Timing
CVSS 3.1
CVE-2023-47579 HIGH
Relyum RELY-PCIe 22.2.1 - Unauthenticated Password Hash Exposure via System Group Misconfiguration
CVSS 7.5
CVE-2023-6547 LOW
Mattermost < 8.1.5 - Improper Access Control in Playbook Team Membership Validation
CVSS 3.7
Details
Vulnerabilities 5,306