CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,306 vulnerabilities with CWE-284
CVE-2023-50343
HIGH
HCL DRYiCE MyXalytics - Authenticated Improper Access Control via Controller APIs
CVSS 8.3
CVE-2023-50341
HIGH
HCL DRYiCE MyXalytics - Improper Access Control via Obsolete Web Pages
CVSS 7.6
CVE-2023-50333
LOW
Mattermost < 8.1.7 - Improper Access Control via Session Permission Update
CVSS 3.7
CVE-2023-47858
MEDIUM
Mattermost < 8.1.7, < 7.8.10 - Improper Access Control via Archived Public Channel Endpoint
CVSS 4.3
CVE-2023-7193
MEDIUM
MTab Bookmark < 1.2.6 - Improper Access Control in Installation Component
CVSS 4.6
CVE-2023-50928
HIGH
awslabs_sandbox_accounts_for_events < 1.1.0 - Authenticated Improper Access Control via Non-Existent Event ID
CVSS 7.1
CVE-2023-49791
MEDIUM
Nextcloud Server 23.0.0-23.0.12.12, 26.0.0-26.0.8 - Improper Access Control via API Bypass
CVSS 5.4
CVE-2023-51661
HIGH
Wasmer <4.2.4 - Privilege Escalation
CVSS 8.4
CVE-2023-7055
MEDIUM
PHPGurukul Online Notes Sharing System 1.0 - Improper Access Control via Profile Mobile Number Parameter
CVSS 4.3
CVE-2023-50783
MEDIUM
Apache Airflow < 2.8.0 - Authenticated Unauthorized Variable Modification
CVSS 6.5
CVE-2023-7025
HIGH
KylinSoft hedron-domain-hook < 3.8.0.12-0k0.5 - Improper Access Control in DBus Handler
CVSS 7.8
CVE-2023-51390
MEDIUM
journalpump <2.5.0 - Info Disclosure
CVSS 6.5
CVE-2023-50706
MEDIUM
efacec UC_500E Firmware - Unauthenticated Sensitive Information Exposure via Memory Dump
CVSS 4.1
CVE-2023-6930
CRITICAL
EuroTel ETL3100 v01c01 and v01x37 - Unauthenticated Sensitive Information Disclosure via Configuration and Log Download
CVSS 9.4
CVE-2023-51384
MEDIUM
OpenSSH <9.6 - Privilege Escalation
CVSS 5.5
CVE-2023-48441
MEDIUM
Adobe Experience Manager <6.5.18 - Info Disclosure
CVSS 5.3
CVE-2023-21751
MEDIUM
Azure DevOps Server - Open Redirect
CVSS 6.5
CVE-2023-50440
MEDIUM
PRIMX ZED! ZEDMAIL ZONECENTRAL ZEDFREE ZEDPRO < 2023.5 - Unauthenticated Access Control Bypass via UNC Injection
CVSS 5.5
CVE-2023-6773
MEDIUM
CodeAstro POS and Inventory Management System 1.0 - Improper Access Control via User Creation Handler
CVSS 4.3
CVE-2023-6761
MEDIUM
IceCMS <= 2.0.1 - Improper Access Control in User Data Handler
CVSS 4.3
CVE-2023-6758
MEDIUM
Thecosy IceCMS 2.0.1 - Improper Access Control in PlanetCommentList API
CVSS 5.3
CVE-2023-47325
MEDIUM
Silverpeas < 6.3.2 - Broken Access Control in Administrative Bin Feature
CVSS 5.4
CVE-2023-47536
LOW
FortiOS/FortiProxy Unauthenticated Firewall Policy Bypass via GeoIP Update Timing
CVSS 3.1
CVE-2023-47579
HIGH
Relyum RELY-PCIe 22.2.1 - Unauthenticated Password Hash Exposure via System Group Misconfiguration
CVSS 7.5
CVE-2023-6547
LOW
Mattermost < 8.1.5 - Improper Access Control in Playbook Team Membership Validation
CVSS 3.7
Details
Vulnerabilities
5,306