CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-22250 MEDIUM
Adobe Commerce <2.4.4-p2, 2.4.5-p1 - Auth Bypass
CVSS 5.3
CVE-2023-1647 HIGH
GitHub calcom/cal.com <2.7 - Info Disclosure
CVSS 8.8
CVE-2023-28443 MEDIUM
Directus < 9.23.3 - Unauthenticated Token Exposure via Log Output
CVSS 4.2
CVE-2023-26360 HIGH KEV
Adobe ColdFusion <2018 Update 15, 2021 Update 5 - RCE
CVSS 8.6
CVE-2023-20065 HIGH
Cisco IOS XE - Privilege Escalation
CVSS 7.8
CVE-2023-1557 MEDIUM
SourceCodester E-Commerce System 1.0 - Improper Access Controls
CVSS 6.3
CVE-2023-25595 MEDIUM
ClearPass Policy Manager - Information Disclosure via OnGuard Ubuntu Agent
CVSS 5.5
CVE-2023-27578 CRITICAL
Galaxy < 22.01 - Improper Access Control in Visualization and Page Management
CVSS 9.1
CVE-2023-1491 MEDIUM
Max Secure Anti Virus Plus 19.0.2.1 - Improper Access Controls
CVSS 4.4
CVE-2023-1490 MEDIUM
Max Secure Anti Virus Plus 19.0.2.1 - Improper Access Controls
CVSS 4.4
CVE-2023-1489 HIGH
Lespeed WiseCleaner Wise System Monitor <1.5.3.54 - Improper Access...
CVSS 7.8
CVE-2023-1486 MEDIUM
Lespeed WiseCleaner Wise Force Deleter <1.5.3.54 - Improper Access ...
CVSS 4.4
CVE-2023-1453 MEDIUM
Watchdog Anti-Virus 1.4.214.0 - Info Disclosure
CVSS 4.4
CVE-2023-28531 CRITICAL
OpenSSH <9.3 - Privilege Escalation
CVSS 9.8
CVE-2023-21465 MEDIUM
BixbyTouch < 3.2.02.5 - Unauthenticated Local File Access via Improper Access Control
CVSS 5.5
CVE-2023-21463 MEDIUM
Samsung MyFiles < 12.2.09.0 - Improper Access Control
CVSS 4.0
CVE-2023-21457 MEDIUM
Samsung Android - Unauthenticated Improper Access Control via Bluetooth File Transfer
CVSS 4.1
CVE-2023-0811 CRITICAL
Omron SYSMAC CJ2H and CJ2M Firmware - Unauthenticated Improper Access Control via PROGRAM AREA WRITE Command
CVSS 9.1
CVE-2023-27875 HIGH
IBM Aspera Faspex 5.0.4 - Improper Access Control
CVSS 7.5
CVE-2023-1432 HIGH
SourceCodester Online Food Ordering System 2.0 - Improper Access Co...
CVSS 7.3
CVE-2023-24468 CRITICAL
Advanced Authentication <6.4.1.1-6.3.7.2 - Privilege Escalation
CVSS 9.8
CVE-2023-27268 MEDIUM
SAP NetWeaver AS Java 7.50 - Privilege Escalation
CVSS 5.3
CVE-2023-26460 MEDIUM
SAP NetWeaver Application Server for Java 7.50 - Auth Bypass
CVSS 5.3
CVE-2023-23911 HIGH
rocket.chat < 6.0.0 - Improper Access Control via Group Key Manipulation
CVSS 7.5
CVE-2023-27088 HIGH
feiqu-opensource - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 5,306