CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-21985 HIGH
Oracle Solaris <11 - Privilege Escalation
CVSS 7.7
CVE-2023-21980 HIGH
MySQL < 5.7.41 and 8.0.32 - Authenticated Remote Code Execution via Client Programs
CVSS 7.1
CVE-2023-21969 MEDIUM
Oracle SQL Developer <23.1.0 - Takeover
CVSS 6.7
CVE-2023-21968 LOW
Oracle Java SE <20 - Unauthenticated RCE
CVSS 3.7
CVE-2023-21923 HIGH
Oracle Health Sciences InForm <6.3.1.3-7.0.0.1 - RCE
CVSS 8.3
CVE-2023-21922 MEDIUM
Oracle Health Sciences InForm <6.3.1.3,7.0.0.1 - Info Disclosure
CVSS 6.8
CVE-2023-21905 MEDIUM
Oracle Banking Virtual Account Management <14.8 - Privilege Escalation
CVSS 6.1
CVE-2023-30539 MEDIUM
Nextcloud Files Automated Tagging 1.14.0-1.14.1 - Improper Access Control
CVSS 6.5
CVE-2023-2104 MEDIUM
alextselegidis/easyappointments <1.5.0 - Info Disclosure
CVSS 5.4
CVE-2023-26408 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - RCE
CVSS 7.8
CVE-2023-26406 HIGH
Adobe Acrobat Reader <23.001.20093,20.005.30441 - RCE
CVSS 7.8
CVE-2023-28808 CRITICAL
Hikvision Hybrid SAN/Cluster Storage - Privilege Escalation
CVSS 9.1
CVE-2023-28312 MEDIUM
Azure Machine Learning 3.0.0-3.0.02199.0001 - Information Disclosure
CVSS 6.5
CVE-2023-28300 HIGH
Azure Service Connector < 0.3.0 - Security Feature Bypass
CVSS 7.5
CVE-2023-28246 HIGH
Windows 11 21H2/22H2 & Server 2022 Elevation of Privilege via Registry Access Control
CVSS 7.8
CVE-2023-24544 HIGH
Buffalo network devices < - Info Disclosure
CVSS 8.1
CVE-2023-23575 MEDIUM
Contec Cps-mg341-adsc1-111 Firmware < 3.7.10 - Improper Access Control
CVSS 4.3
CVE-2023-28051 HIGH
Dell Power Manager < 3.11 - Privilege Escalation via Improper Access Control
CVSS 7.8
CVE-2023-0319 MEDIUM
GitLab <15.8.5-15.9.4-15.10.1 - Info Disclosure
CVSS 5.8
CVE-2023-1883 MEDIUM
thorsten/phpmyfaq <3.1.12 - Info Disclosure
CVSS 5.4
CVE-2023-28845 LOW
Nextcloud talk <14.0.9-15.0.4 - Info Disclosure
CVSS 3.5
CVE-2023-28844 MEDIUM
Nextcloud Server 24.0.4-24.0.9 - Improper Access Control via File Version Download
CVSS 5.7
CVE-2023-28645 MEDIUM
Nextcloud richdocuments <8.0.0-beta.1-6.3.2 - Auth Bypass
CVSS 5.7
CVE-2023-29140 MEDIUM
MediaWiki <1.39.3 - Info Disclosure
CVSS 5.3
CVE-2023-28877 HIGH
VTEX [email protected] - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 5,306