CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,306 vulnerabilities with CWE-284
CVE-2023-0858
LOW
Canon MF/LBP Series Firmware < 11.04 - Unauthenticated Improper Access Control
CVSS 3.1
CVE-2023-25771
MEDIUM
Intel NUC BIOS Firmware - Denial of Service via Improper Access Control
CVSS 5.8
CVE-2023-23573
MEDIUM
Intel Unite < 17 - Information Disclosure via Improper Access Control
CVSS 4.4
CVE-2023-22312
HIGH
Intel(R) NUC BIOS - Privilege Escalation
CVSS 7.2
CVE-2023-24905
HIGH
Microsoft Remote Desktop Client - Remote Code Execution
CVSS 7.8
CVE-2023-32060
MEDIUM
DHIS2 2.35.0-2.36.12 - Improper Access Control in Tracked Entity and Events API Endpoints
CVSS 6.5
CVE-2023-31138
HIGH
DHIS2 Core <2.37.9.1-2.39.1.2 - Privilege Escalation
CVSS 7.1
CVE-2023-21495
MEDIUM
Samsung Android Knox Enrollment Service - Improper Access Control
CVSS 4.0
CVE-2023-21493
MEDIUM
Samsung Android - Improper Access Control in SemShareFileProvider
CVSS 6.8
CVE-2023-21491
HIGH
Samsung Android ThemeManager - Unauthenticated Arbitrary File Write with System Privileges
CVSS 8.5
CVE-2023-21490
MEDIUM
Samsung Android - Improper Access Control in GearManagerStub
CVSS 4.7
CVE-2023-21488
MEDIUM
Samsung Android Tips < May-2023 Release 1 - Improper Access Control
CVSS 4.4
CVE-2023-28070
MEDIUM
Alienware Command Center < 5.5.46.0 - Privilege Escalation via Installation or Update Process
CVSS 6.7
CVE-2023-21642
HIGH
Qualcomm HAB Memory Management Firmware - Memory Corruption
CVSS 8.4
CVE-2023-2429
CRITICAL
phpmyfaq < 3.1.13 - Improper Access Control
CVSS 9.8
CVE-2023-25496
HIGH
Lenovo Drivers Management < 3.1.1307.1308 - Privilege Escalation
CVSS 7.8
CVE-2023-24512
HIGH
Arista EOS 4.26.0-4.26.10m - Authenticated Arbitrary Configuration Update via gNMI Request
CVSS 8.8
CVE-2023-29924
CRITICAL
PowerJob V4.3.1 - Remote Code Execution via Improper Access Control
CVSS 9.8
CVE-2023-2202
MEDIUM
rosariosis < 10.9.3 - Improper Access Control
CVSS 6.5
CVE-2023-27350
CRITICAL
KEV
PaperCut MF and NG 8.0-20.1.7 - Unauthenticated Remote Code Execution via SetupCompleted
CVSS 9.8
CVE-2023-2112
LOW
M-Files <23.4.12455.0 - Privilege Escalation
CVSS 3.6
CVE-2023-29922
MEDIUM
PowerJob V4.3.1 - Improper Access Control via User Creation Interface
CVSS 5.3
CVE-2023-29586
MEDIUM
Code Sector TeraCopy 3.9.7 - Arbitrary File Read via Improper Access Control
CVSS 5.5
CVE-2023-29921
MEDIUM
PowerJob V4.3.1 - Improper Access Control via Create App Interface
CVSS 5.3
CVE-2023-29513
MEDIUM
XWiki < 14.10.1 - Unauthenticated User Creation via Distribution First Admin User Endpoint
CVSS 5.0
Details
Vulnerabilities
5,306