CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,306 vulnerabilities with CWE-284
CVE-2023-40730
HIGH
QMS Automotive <V12.39 - Privilege Escalation
CVSS 7.1
CVE-2023-3039
HIGH
SD ROM Utility <1.0.2.0 - Code Injection
CVSS 7.3
CVE-2023-40039
CRITICAL
ARRIS TG852G TG862G TG1672G - Unauthenticated WPA2-PSK Derivation via Beacon Frame
CVSS 9.8
CVE-2023-37759
CRITICAL
Crypto Currency Tracker < 9.5 - Unauthenticated Admin Registration via User Registration Page
CVSS 9.8
CVE-2023-40060
HIGH
SolarWinds Serv-U 15.4-15.4 Hotfix 1 - Authenticated Multi-Factor Authentication Bypass
CVSS 7.2
CVE-2023-36635
HIGH
Fortinet FortiSwitchManager <7.2.2, <7.0.1 - Privilege Escalation
CVSS 7.1
CVE-2023-31242
HIGH
Open Automation Software OAS Platform <18.00.0072 - Auth Bypass
CVSS 8.1
CVE-2023-4696
CRITICAL
memos < 0.13.2 - Improper Access Control
CVSS 9.8
CVE-2023-4650
MEDIUM
instantcms < 2.16.1 - Improper Access Control
CVSS 4.7
CVE-2023-4640
MEDIUM
YugabyteDB Anywhere <2.17.3 - Info Disclosure
CVSS 6.5
CVE-2023-40170
MEDIUM
jupyter_server < 2.7.2 - Improper Access Control in Files Endpoint
CVSS 4.6
CVE-2023-4546
LOW
Byzoro Smart S85F Management Platform <20230816 - Info Disclosure
CVSS 3.5
CVE-2023-40579
MEDIUM
OpenFGA < 1.3.1 - Authorization Bypass via ListObjects API
CVSS 6.5
CVE-2023-40573
CRITICAL
XWiki < 14.10.9 - Remote Code Execution via Scheduled Job Script Injection
CVSS 9.0
CVE-2023-20230
MEDIUM
Cisco Application Policy Infrastructure Controller 5.2-5.2(8d) - Authenticated Improper Access Control
CVSS 5.4
CVE-2023-38132
HIGH
LAN-W451NGR - Unauthenticated Telnet Access via Improper Access Control
CVSS 8.8
CVE-2023-39973
MEDIUM
AcyMailing 6.7.0-8.7.0 - Unauthenticated Improper Access Control
CVSS 4.3
CVE-2023-39972
MEDIUM
AcyMailing 6.7.0-8.7.0 - Unauthenticated Improper Access Control
CVSS 4.3
CVE-2023-36106
HIGH
powerjob < 4.3.2 - Unauthenticated Sensitive Information Exposure via /container/list appId Parameter
CVSS 7.5
CVE-2023-39743
MEDIUM
lzma_software_development_kit 23.01 - Access Violation in bz3_decode_block
CVSS 5.3
CVE-2023-20237
MEDIUM
Cisco Intersight Virtual Appliance - Unauthenticated Access
CVSS 4.3
CVE-2023-20224
HIGH
Cisco ThousandEyes Enterprise Agent - Privilege Escalation
CVSS 7.8
CVE-2023-32609
MEDIUM
Intel Unite < 4.2.3504 - Authenticated Information Disclosure via Local Access
CVSS 5.0
CVE-2023-32285
MEDIUM
Intel NUC BIOS Firmware - Denial of Service via Improper Access Control
CVSS 6.0
CVE-2023-28714
HIGH
Intel PROSet/Wireless <22.220 HF - Privilege Escalation
CVSS 8.2
Details
Vulnerabilities
5,306