CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-40730 HIGH
QMS Automotive <V12.39 - Privilege Escalation
CVSS 7.1
CVE-2023-3039 HIGH
SD ROM Utility <1.0.2.0 - Code Injection
CVSS 7.3
CVE-2023-40039 CRITICAL
ARRIS TG852G TG862G TG1672G - Unauthenticated WPA2-PSK Derivation via Beacon Frame
CVSS 9.8
CVE-2023-37759 CRITICAL
Crypto Currency Tracker < 9.5 - Unauthenticated Admin Registration via User Registration Page
CVSS 9.8
CVE-2023-40060 HIGH
SolarWinds Serv-U 15.4-15.4 Hotfix 1 - Authenticated Multi-Factor Authentication Bypass
CVSS 7.2
CVE-2023-36635 HIGH
Fortinet FortiSwitchManager <7.2.2, <7.0.1 - Privilege Escalation
CVSS 7.1
CVE-2023-31242 HIGH
Open Automation Software OAS Platform <18.00.0072 - Auth Bypass
CVSS 8.1
CVE-2023-4696 CRITICAL
memos < 0.13.2 - Improper Access Control
CVSS 9.8
CVE-2023-4650 MEDIUM
instantcms < 2.16.1 - Improper Access Control
CVSS 4.7
CVE-2023-4640 MEDIUM
YugabyteDB Anywhere <2.17.3 - Info Disclosure
CVSS 6.5
CVE-2023-40170 MEDIUM
jupyter_server < 2.7.2 - Improper Access Control in Files Endpoint
CVSS 4.6
CVE-2023-4546 LOW
Byzoro Smart S85F Management Platform <20230816 - Info Disclosure
CVSS 3.5
CVE-2023-40579 MEDIUM
OpenFGA < 1.3.1 - Authorization Bypass via ListObjects API
CVSS 6.5
CVE-2023-40573 CRITICAL
XWiki < 14.10.9 - Remote Code Execution via Scheduled Job Script Injection
CVSS 9.0
CVE-2023-20230 MEDIUM
Cisco Application Policy Infrastructure Controller 5.2-5.2(8d) - Authenticated Improper Access Control
CVSS 5.4
CVE-2023-38132 HIGH
LAN-W451NGR - Unauthenticated Telnet Access via Improper Access Control
CVSS 8.8
CVE-2023-39973 MEDIUM
AcyMailing 6.7.0-8.7.0 - Unauthenticated Improper Access Control
CVSS 4.3
CVE-2023-39972 MEDIUM
AcyMailing 6.7.0-8.7.0 - Unauthenticated Improper Access Control
CVSS 4.3
CVE-2023-36106 HIGH
powerjob < 4.3.2 - Unauthenticated Sensitive Information Exposure via /container/list appId Parameter
CVSS 7.5
CVE-2023-39743 MEDIUM
lzma_software_development_kit 23.01 - Access Violation in bz3_decode_block
CVSS 5.3
CVE-2023-20237 MEDIUM
Cisco Intersight Virtual Appliance - Unauthenticated Access
CVSS 4.3
CVE-2023-20224 HIGH
Cisco ThousandEyes Enterprise Agent - Privilege Escalation
CVSS 7.8
CVE-2023-32609 MEDIUM
Intel Unite < 4.2.3504 - Authenticated Information Disclosure via Local Access
CVSS 5.0
CVE-2023-32285 MEDIUM
Intel NUC BIOS Firmware - Denial of Service via Improper Access Control
CVSS 6.0
CVE-2023-28714 HIGH
Intel PROSet/Wireless <22.220 HF - Privilege Escalation
CVSS 8.2
Details
Vulnerabilities 5,306