CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-0858 LOW
Canon MF/LBP Series Firmware < 11.04 - Unauthenticated Improper Access Control
CVSS 3.1
CVE-2023-25771 MEDIUM
Intel NUC BIOS Firmware - Denial of Service via Improper Access Control
CVSS 5.8
CVE-2023-23573 MEDIUM
Intel Unite < 17 - Information Disclosure via Improper Access Control
CVSS 4.4
CVE-2023-22312 HIGH
Intel(R) NUC BIOS - Privilege Escalation
CVSS 7.2
CVE-2023-24905 HIGH
Microsoft Remote Desktop Client - Remote Code Execution
CVSS 7.8
CVE-2023-32060 MEDIUM
DHIS2 2.35.0-2.36.12 - Improper Access Control in Tracked Entity and Events API Endpoints
CVSS 6.5
CVE-2023-31138 HIGH
DHIS2 Core <2.37.9.1-2.39.1.2 - Privilege Escalation
CVSS 7.1
CVE-2023-21495 MEDIUM
Samsung Android Knox Enrollment Service - Improper Access Control
CVSS 4.0
CVE-2023-21493 MEDIUM
Samsung Android - Improper Access Control in SemShareFileProvider
CVSS 6.8
CVE-2023-21491 HIGH
Samsung Android ThemeManager - Unauthenticated Arbitrary File Write with System Privileges
CVSS 8.5
CVE-2023-21490 MEDIUM
Samsung Android - Improper Access Control in GearManagerStub
CVSS 4.7
CVE-2023-21488 MEDIUM
Samsung Android Tips < May-2023 Release 1 - Improper Access Control
CVSS 4.4
CVE-2023-28070 MEDIUM
Alienware Command Center < 5.5.46.0 - Privilege Escalation via Installation or Update Process
CVSS 6.7
CVE-2023-21642 HIGH
Qualcomm HAB Memory Management Firmware - Memory Corruption
CVSS 8.4
CVE-2023-2429 CRITICAL
phpmyfaq < 3.1.13 - Improper Access Control
CVSS 9.8
CVE-2023-25496 HIGH
Lenovo Drivers Management < 3.1.1307.1308 - Privilege Escalation
CVSS 7.8
CVE-2023-24512 HIGH
Arista EOS 4.26.0-4.26.10m - Authenticated Arbitrary Configuration Update via gNMI Request
CVSS 8.8
CVE-2023-29924 CRITICAL
PowerJob V4.3.1 - Remote Code Execution via Improper Access Control
CVSS 9.8
CVE-2023-2202 MEDIUM
rosariosis < 10.9.3 - Improper Access Control
CVSS 6.5
CVE-2023-27350 CRITICAL KEV
PaperCut MF and NG 8.0-20.1.7 - Unauthenticated Remote Code Execution via SetupCompleted
CVSS 9.8
CVE-2023-2112 LOW
M-Files <23.4.12455.0 - Privilege Escalation
CVSS 3.6
CVE-2023-29922 MEDIUM
PowerJob V4.3.1 - Improper Access Control via User Creation Interface
CVSS 5.3
CVE-2023-29586 MEDIUM
Code Sector TeraCopy 3.9.7 - Arbitrary File Read via Improper Access Control
CVSS 5.5
CVE-2023-29921 MEDIUM
PowerJob V4.3.1 - Improper Access Control via Create App Interface
CVSS 5.3
CVE-2023-29513 MEDIUM
XWiki < 14.10.1 - Unauthenticated User Creation via Distribution First Admin User Endpoint
CVSS 5.0
Details
Vulnerabilities 5,306