CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,306 vulnerabilities with CWE-284
CVE-2023-41721
MEDIUM
UniFi Network Application < 7.5.176 - Improper Access Control in Device Adoption
CVSS 5.3
CVE-2023-39731
MEDIUM
Kaibutsunosato 13.6.1 - Improper Access Control
CVSS 5.3
CVE-2023-46033
MEDIUM
D-Link DSL-2750U/2730U - Privilege Escalation
CVSS 6.8
CVE-2023-20261
MEDIUM
Cisco Catalyst SD-WAN Manager - Info Disclosure
CVSS 6.5
CVE-2023-22102
HIGH
Oracle MySQL <8.1.0 - Info Disclosure
CVSS 8.3
CVE-2023-43814
LOW
Discourse <3.1.1-3.2.0.beta2 - Info Disclosure
CVSS 3.7
CVE-2023-43119
CRITICAL
Extreme Networks Switch Engine <32.5.1.5 - Privilege Escalation
CVSS 9.8
CVE-2023-5240
HIGH
Devolutions Server < 2023.2.8.0 - Authenticated Password Exposure via PAM Propagation Script GET Request
CVSS 7.5
CVE-2023-43079
HIGH
Dell OpenManage Server Administrator <11.0.0.0 - Privilege Escalation
CVSS 7.3
CVE-2023-41882
MEDIUM
vantage6 < 4.0.0 - Improper Access Control in Task Collection Endpoint
CVSS 5.4
CVE-2023-32632
HIGH
Yifan YF325 Firmware v1.0_20221108 - Remote Code Execution via Diag Ping Start
CVSS 8.8
CVE-2023-24479
CRITICAL
Yifan YF325 1.0_20221108 nvram.cgi - Authentication Bypass Command Execution
CVSS 9.8
CVE-2023-44118
CRITICAL
HarmonyOS and EMUI - Improper Access Control in MeeTime Module
CVSS 9.1
CVE-2023-41772
HIGH
Windows 10/11, Server 2019/2022 Elevation of Privilege via Win32k
CVSS 7.8
CVE-2023-36790
HIGH
Windows RDP Encoder Mirror Driver - Privilege Escalation
CVSS 7.8
CVE-2023-36725
HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2023-36722
MEDIUM
Active Directory Domain Services - Info Disclosure
CVSS 4.4
CVE-2023-36561
HIGH
Azure DevOps Server - Privilege Escalation
CVSS 7.3
CVE-2023-41679
HIGH
FortiManager <7.2.2-6.4.11 - Privilege Escalation
CVSS 8.5
CVE-2023-33301
MEDIUM
Fortinet FortiOS <7.2.5-7.4.0 - Info Disclosure
CVSS 6.5
CVE-2023-37194
MEDIUM
SIMATIC CP 1604/1616/1623/1626/1628 - Authenticated Arbitrary Code Execution via DMA
CVSS 6.7
CVE-2023-5365
CRITICAL
HP LIFE < 1.8 - Improper Access Control
CVSS 9.8
CVE-2023-36820
MEDIUM
Micronaut Security <3.1.2-3.11.1 - Info Disclosure
CVSS 4.8
CVE-2023-43696
HIGH
SICK APU0200 Firmware < 4.0.0.6 - Unauthenticated Arbitrary File Read and Write via FTP Server
CVSS 8.2
CVE-2023-36465
CRITICAL
Decidim <0.26.8, <0.27.4 - Privilege Escalation
CVSS 9.1
Details
Vulnerabilities
5,306