CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-41721 MEDIUM
UniFi Network Application < 7.5.176 - Improper Access Control in Device Adoption
CVSS 5.3
CVE-2023-39731 MEDIUM
Kaibutsunosato 13.6.1 - Improper Access Control
CVSS 5.3
CVE-2023-46033 MEDIUM
D-Link DSL-2750U/2730U - Privilege Escalation
CVSS 6.8
CVE-2023-20261 MEDIUM
Cisco Catalyst SD-WAN Manager - Info Disclosure
CVSS 6.5
CVE-2023-22102 HIGH
Oracle MySQL <8.1.0 - Info Disclosure
CVSS 8.3
CVE-2023-43814 LOW
Discourse <3.1.1-3.2.0.beta2 - Info Disclosure
CVSS 3.7
CVE-2023-43119 CRITICAL
Extreme Networks Switch Engine <32.5.1.5 - Privilege Escalation
CVSS 9.8
CVE-2023-5240 HIGH
Devolutions Server < 2023.2.8.0 - Authenticated Password Exposure via PAM Propagation Script GET Request
CVSS 7.5
CVE-2023-43079 HIGH
Dell OpenManage Server Administrator <11.0.0.0 - Privilege Escalation
CVSS 7.3
CVE-2023-41882 MEDIUM
vantage6 < 4.0.0 - Improper Access Control in Task Collection Endpoint
CVSS 5.4
CVE-2023-32632 HIGH
Yifan YF325 Firmware v1.0_20221108 - Remote Code Execution via Diag Ping Start
CVSS 8.8
CVE-2023-24479 CRITICAL
Yifan YF325 1.0_20221108 nvram.cgi - Authentication Bypass Command Execution
CVSS 9.8
CVE-2023-44118 CRITICAL
HarmonyOS and EMUI - Improper Access Control in MeeTime Module
CVSS 9.1
CVE-2023-41772 HIGH
Windows 10/11, Server 2019/2022 Elevation of Privilege via Win32k
CVSS 7.8
CVE-2023-36790 HIGH
Windows RDP Encoder Mirror Driver - Privilege Escalation
CVSS 7.8
CVE-2023-36725 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2023-36722 MEDIUM
Active Directory Domain Services - Info Disclosure
CVSS 4.4
CVE-2023-36561 HIGH
Azure DevOps Server - Privilege Escalation
CVSS 7.3
CVE-2023-41679 HIGH
FortiManager <7.2.2-6.4.11 - Privilege Escalation
CVSS 8.5
CVE-2023-33301 MEDIUM
Fortinet FortiOS <7.2.5-7.4.0 - Info Disclosure
CVSS 6.5
CVE-2023-37194 MEDIUM
SIMATIC CP 1604/1616/1623/1626/1628 - Authenticated Arbitrary Code Execution via DMA
CVSS 6.7
CVE-2023-5365 CRITICAL
HP LIFE < 1.8 - Improper Access Control
CVSS 9.8
CVE-2023-36820 MEDIUM
Micronaut Security <3.1.2-3.11.1 - Info Disclosure
CVSS 4.8
CVE-2023-43696 HIGH
SICK APU0200 Firmware < 4.0.0.6 - Unauthenticated Arbitrary File Read and Write via FTP Server
CVSS 8.2
CVE-2023-36465 CRITICAL
Decidim <0.26.8, <0.27.4 - Privilege Escalation
CVSS 9.1
Details
Vulnerabilities 5,306