CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,306 vulnerabilities with CWE-284
CVE-2023-22250
MEDIUM
Adobe Commerce <2.4.4-p2, 2.4.5-p1 - Auth Bypass
CVSS 5.3
CVE-2023-1647
HIGH
GitHub calcom/cal.com <2.7 - Info Disclosure
CVSS 8.8
CVE-2023-28443
MEDIUM
Directus < 9.23.3 - Unauthenticated Token Exposure via Log Output
CVSS 4.2
CVE-2023-26360
HIGH
KEV
Adobe ColdFusion <2018 Update 15, 2021 Update 5 - RCE
CVSS 8.6
CVE-2023-20065
HIGH
Cisco IOS XE - Privilege Escalation
CVSS 7.8
CVE-2023-1557
MEDIUM
SourceCodester E-Commerce System 1.0 - Improper Access Controls
CVSS 6.3
CVE-2023-25595
MEDIUM
ClearPass Policy Manager - Information Disclosure via OnGuard Ubuntu Agent
CVSS 5.5
CVE-2023-27578
CRITICAL
Galaxy < 22.01 - Improper Access Control in Visualization and Page Management
CVSS 9.1
CVE-2023-1491
MEDIUM
Max Secure Anti Virus Plus 19.0.2.1 - Improper Access Controls
CVSS 4.4
CVE-2023-1490
MEDIUM
Max Secure Anti Virus Plus 19.0.2.1 - Improper Access Controls
CVSS 4.4
CVE-2023-1489
HIGH
Lespeed WiseCleaner Wise System Monitor <1.5.3.54 - Improper Access...
CVSS 7.8
CVE-2023-1486
MEDIUM
Lespeed WiseCleaner Wise Force Deleter <1.5.3.54 - Improper Access ...
CVSS 4.4
CVE-2023-1453
MEDIUM
Watchdog Anti-Virus 1.4.214.0 - Info Disclosure
CVSS 4.4
CVE-2023-28531
CRITICAL
OpenSSH <9.3 - Privilege Escalation
CVSS 9.8
CVE-2023-21465
MEDIUM
BixbyTouch < 3.2.02.5 - Unauthenticated Local File Access via Improper Access Control
CVSS 5.5
CVE-2023-21463
MEDIUM
Samsung MyFiles < 12.2.09.0 - Improper Access Control
CVSS 4.0
CVE-2023-21457
MEDIUM
Samsung Android - Unauthenticated Improper Access Control via Bluetooth File Transfer
CVSS 4.1
CVE-2023-0811
CRITICAL
Omron SYSMAC CJ2H and CJ2M Firmware - Unauthenticated Improper Access Control via PROGRAM AREA WRITE Command
CVSS 9.1
CVE-2023-27875
HIGH
IBM Aspera Faspex 5.0.4 - Improper Access Control
CVSS 7.5
CVE-2023-1432
HIGH
SourceCodester Online Food Ordering System 2.0 - Improper Access Co...
CVSS 7.3
CVE-2023-24468
CRITICAL
Advanced Authentication <6.4.1.1-6.3.7.2 - Privilege Escalation
CVSS 9.8
CVE-2023-27268
MEDIUM
SAP NetWeaver AS Java 7.50 - Privilege Escalation
CVSS 5.3
CVE-2023-26460
MEDIUM
SAP NetWeaver Application Server for Java 7.50 - Auth Bypass
CVSS 5.3
CVE-2023-23911
HIGH
rocket.chat < 6.0.0 - Improper Access Control via Group Key Manipulation
CVSS 7.5
CVE-2023-27088
HIGH
feiqu-opensource - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities
5,306