CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-24490 MEDIUM
Citrix Virtual Apps and Desktops < 2305 - Improper Access Control
CVSS 6.3
CVE-2023-24489 CRITICAL KEV
Citrix ShareFile Storage Zones Controller - Unauthenticated Remote Compromise
CVSS 9.8
CVE-2023-24486 MEDIUM
Citrix Workspace app for Linux - Privilege Escalation
CVSS 5.5
CVE-2023-3273 HIGH
SICK ICR890-4 Firmware < 2.5.0 - Unauthenticated Improper Access Control
CVSS 7.5
CVE-2023-3271 HIGH
SICK ICR890-4 Firmware < 2.5.0 - Unauthenticated Information Disclosure via REST API
CVSS 8.2
CVE-2023-35940 HIGH
GLPI 9.5.0-10.0.8 - Unauthenticated Dashboard Data Access via Incorrect Rights Check
CVSS 7.5
CVE-2023-35939 HIGH
GLPI <10.0.8 - Privilege Escalation
CVSS 8.1
CVE-2023-34107 MEDIUM
GLPI 9.2.0-10.0.7 - Authenticated Incorrect Access Control in KnowbaseItems
CVSS 6.5
CVE-2023-34106 MEDIUM
GLPI <10.0.8 - Privilege Escalation
CVSS 6.5
CVE-2023-21518 MEDIUM
SearchWidget <3.3 - Privilege Escalation
CVSS 4.4
CVE-2023-3431 MEDIUM
PlantUML < 1.2023.9 - Improper Access Control
CVSS 5.3
CVE-2023-35927 HIGH
NextCloud Server <26.0.2 - Privilege Escalation
CVSS 7.6
CVE-2023-35173 MEDIUM
Nextcloud End-to-end Encryption 1.12.0-1.12.3 - Denial of Service via Invalid Metadata File
CVSS 5.7
CVE-2023-35167 MEDIUM
remult < 0.20.6 - Improper Access Control via apiPrefilter Function
CVSS 5.0
CVE-2023-3304 MEDIUM
admidio/admidio <4.2.9 - Info Disclosure
CVSS 5.4
CVE-2023-3303 LOW
admidio/admidio <4.2.9 - Info Disclosure
CVSS 3.5
CVE-2023-1862 HIGH
Cloudflare WARP client <v2023.3.381.0 - Code Injection
CVSS 7.3
CVE-2023-3306 HIGH
Ruijie RG-EW1200G EW_3.0(1)B11P204 - Info Disclosure
CVSS 7.3
CVE-2023-3305 HIGH
C-DATA Web Management System <20230607 - Improper Access Controls
CVSS 7.3
CVE-2023-28810 MEDIUM
Access Control/Intercom < - Info Disclosure
CVSS 4.3
CVE-2023-28809 HIGH
Hikvision Access Control Devices - Session Hijacking via Reused Session ID
CVSS 7.5
CVE-2023-32009 HIGH
Windows Collaborative Translation Framework - Privilege Escalation
CVSS 8.8
CVE-2023-24546 HIGH
Arista CloudVision Portal - Info Disclosure
CVSS 8.1
CVE-2023-2159 MEDIUM
CMP - Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.7 - Maintenance Mode Bypass via cmp_bypass Parameter
CVSS 5.3
CVE-2023-2183 MEDIUM
Grafana 8.0.0-8.5.25 - Unauthenticated Test Alert Abuse via API
CVSS 4.1
Details
Vulnerabilities 5,306