CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-46759 HIGH
HarmonyOS - Improper Access Control in Call Module
CVSS 7.5
CVE-2023-46755 MEDIUM
Huawei EMUI and HarmonyOS - Denial of Service via Input Parameter Verification Bypass
CVSS 5.3
CVE-2023-46501 CRITICAL
BoltWire 6.03 - Unauthenticated Sensitive Information Disclosure and Password Change
CVSS 9.1
CVE-2023-42542 LOW
Samsung Push Service < 3.4.10 - Improper Access Control
CVSS 3.3
CVE-2023-42540 MEDIUM
Samsung Account < 14.5.01.1 - Improper Access Control via Implicit Intent
CVSS 4.0
CVE-2023-5976 MEDIUM
microweber < 2.0.0 - Improper Access Control
CVSS 4.3
CVE-2023-36620 MEDIUM
Boomerang Parental Control <13.83 - Info Disclosure
CVSS 4.6
CVE-2023-31020 MEDIUM
NVIDIA GPU Display Driver - Privilege Escalation
CVSS 6.1
CVE-2023-31019 HIGH
NVIDIA GPU Display Driver - Privilege Escalation
CVSS 7.8
CVE-2023-43336 HIGH
Sangoma Technologies FreePBX - Info Disclosure
CVSS 8.8
CVE-2023-5916 MEDIUM
Lissy93 Dashy 2.1.1 - Improper Access Control in Configuration Handler
CVSS 4.3
CVE-2023-20267 MEDIUM
Cisco Firepower Threat Defense 6.7.0-7.3.1.1 - Unauthenticated IP Geolocation Rule Bypass
CVSS 4.0
CVE-2023-5833 HIGH
AnythingLLM < 0.1.0 - Improper Access Control
CVSS 8.8
CVE-2023-46665 CRITICAL
Sielco PolyEco1000 - Authentication Bypass via Password Modification
CVSS 9.8
CVE-2023-46664 HIGH
Sielco PolyEco1000 - Privilege Escalation
CVSS 7.5
CVE-2023-46663 HIGH
Sielco PolyEco1000 - Improper Access Control via Unauthorized HTTP Requests
CVSS 7.5
CVE-2023-46662 HIGH
Sielco PolyEco1000 - Info Disclosure
CVSS 7.5
CVE-2023-46661 CRITICAL
Sielco PolyEco1000 - Privilege Escalation
CVSS 9.8
CVE-2023-46666 MEDIUM
Elastic Sharepoint Online Python Connector - Info Disclosure
CVSS 5.3
CVE-2023-45228 MEDIUM
Sielco Analog FM Transmitter Firmware - Unauthenticated Improper Access Control via User Edit Parameters
CVSS 6.5
CVE-2023-42769 CRITICAL
Sielco Analog FM Transmitter Firmware - Unauthenticated Session ID Brute Force and Authentication Bypass
CVSS 9.8
CVE-2023-30969 HIGH
Palantir Tiles < 4.326.0 - Unauthenticated Improper Access Control
CVSS 8.2
CVE-2023-38848 HIGH
rmc R Beauty CLINIC Line <13.6.1 - Info Disclosure
CVSS 7.5
CVE-2023-45844 MEDIUM
Bosch Rexroth ctrlX HMI Web Panel WR2107/WR2110/WR2115 Firmware - Improper Access Control in Kiosk Mode
CVSS 6.8
CVE-2023-44794 CRITICAL
Dromara Sa-Token < 1.37.0 - Privilege Escalation via Crafted Payload
CVSS 9.8
Details
Vulnerabilities 5,306