CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-25605 HIGH
Fortinet FortiSOAR 7.3.0-7.3.1 - Authenticated Improper Access Control via Crafted HTTP Requests
CVSS 7.5
CVE-2023-22335 HIGH
Rakuraku PC Cloud Agent < 2.1.8 and SS1 < 13.0.0.40 - Unauthenticated Arbitrary File Read via Improper Access Control
CVSS 7.5
CVE-2023-26474 CRITICAL
XWiki 13.10-13.10.10 - Improper Access Control via Text Area Property Execution
CVSS 9.9
CVE-2023-26473 MEDIUM
XWiki Platform <1.3-rc-1 - Info Disclosure
CVSS 6.5
CVE-2023-26471 CRITICAL
XWiki 11.6-13.10.9 - Authenticated Privilege Escalation via Async Macro
CVSS 9.9
CVE-2023-23508 MEDIUM
macOS 11.0-11.7.2 - Privacy Preferences Bypass via Improper Access Control
CVSS 5.5
CVE-2023-25821 MEDIUM
Nextcloud Server 24.0.4-24.0.6 and 25.0.0 - Improper Access Control via Reshare Permissions
CVSS 5.7
CVE-2023-1007 MEDIUM
Twister Antivirus 8.17 - Improper Access Control in IoControlCode Handler
CVSS 5.3
CVE-2023-0998 MEDIUM
Alphaware Simple E-Commerce System 1.0 - Improper Access Control in Payment Handler
CVSS 6.5
CVE-2023-0963 HIGH
SourceCodester Music Gallery Site 1.0 - Improper Access Control in Users.php POST Request Handler
CVSS 7.3
CVE-2023-24320 CRITICAL
Axcora POS <gitf77ec09 - Command Injection
CVSS 9.8
CVE-2023-22920 CRITICAL
Zyxel LTE3316-M604 V2.00(ABMP.6)C0 - Unauthenticated Remote Access via Telnet Misconfiguration
CVSS 9.8
CVE-2023-0916 MEDIUM
Auto Dealer Management System 1.0 - Improper Access Control in Users.php
CVSS 6.3
CVE-2023-22232 MEDIUM
Adobe Connect <11.4.5, 12.1.5 - Auth Bypass
CVSS 5.3
CVE-2023-23923 HIGH
Moodle < 3.9.19 - Improper Access Control via Start Page Preference
CVSS 8.2
CVE-2023-24485 HIGH
Citrix Workspace app - Privilege Escalation
CVSS 7.8
CVE-2023-24484 MEDIUM
Citrix Workspace < 2212 - Improper Access Control
CVSS 5.5
CVE-2023-23752 MEDIUM KEV
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
CVSS 5.3
CVE-2023-22807 CRITICAL
LS ELECTRIC XBC-DN32U Firmware 01.80 - Improper Access Control via XGT Protocol
CVSS 9.8
CVE-2023-22805 MEDIUM
LS ELECTRIC XBC-DN32U 01.80 - Improper Access Control in Read Prohibition Feature
CVSS 6.5
CVE-2023-20927 HIGH
Android 13 - Local Privilege Escalation via Signature Permission Bypass
CVSS 7.8
CVE-2023-21777 HIGH
Azure App Service on Azure Stack Hub - Privilege Escalation
CVSS 8.7
CVE-2023-21717 HIGH
Microsoft SharePoint Server - Privilege Escalation
CVSS 8.8
CVE-2023-25149 HIGH
TimescaleDB 2.8.0-2.9.2 - Privilege Escalation via Telemetry Job Search Path
CVSS 8.8
CVE-2023-23835 MEDIUM
Mendix <7.23.34, <8.18.23, <9.22.0, <9.12.10, <9.18.4, <9.6.15 - Au...
CVSS 5.9
Details
Vulnerabilities 5,306