CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-25161 LOW
Nextcloud Server < 23.0.12, 24.0.8, 25.0.1 - Denial of Service via Password Reset Rate Limit Bypass
CVSS 3.7
CVE-2023-25159 LOW
Nextcloud Server 24.0.4-24.0.7 and 25.0.0 - Improper Access Control in Preview Watermark
CVSS 2.3
CVE-2023-0661 MEDIUM
Devolutions Server 2022.3.1.0-2022.3.10.0 - Authenticated Improper Access Control
CVSS 6.5
CVE-2023-24688 MEDIUM
mojoportal 2.7.0.0 - Unauthenticated User Registration Bypass
CVSS 5.3
CVE-2023-21447 MEDIUM
Samsung Cloud < 5.3.0.32 - Improper Access Control via Implicit Intent
CVSS 4.0
CVE-2023-21445 MEDIUM
Samsung Android MyFiles < 12.2.09/13.1.03.501/14.1.00.422 - Unauthenticated Arbitrary File Write via Implicit Intent
CVSS 5.5
CVE-2023-21442 MEDIUM
Samsung Android Runestone < 2.9.09.003 (R) and < 3.2.01.007 (S) - Unauthenticated Device Location Information Disclosure
CVSS 4.0
CVE-2023-21438 LOW
Samsung Android - Improper Access Control in HomeScreen
CVSS 2.1
CVE-2023-21427 MEDIUM
Samsung Android - Improper Access Control in NfcTile
CVSS 5.4
CVE-2023-25150 MEDIUM
Nextcloud richdocuments < 3.8.7 - Improper Access Control via Collabora Integration
CVSS 5.8
CVE-2023-0744 CRITICAL
answerdev/answer < 1.0.4 - Account Takeover via Improper Access Control
CVSS 9.8
CVE-2023-23615 MEDIUM
Discourse < 3.0.0 - Unauthenticated Topic Creation via Embeddable Comments
CVSS 5.3
CVE-2023-24425 MEDIUM
Jenkins Kubernetes Credentials Provider Plugin <1.208 - Privilege E...
CVSS 6.5
CVE-2023-24022 CRITICAL
Baicells Nova - Hardcoded Credentials
CVSS 10.0
CVE-2023-0451 HIGH
Econolite EOS < 3.2.23 - Unauthenticated Sensitive Information Exposure via Log and Configuration Files
CVSS 7.5
CVE-2023-22960 HIGH
Lexmark B2236 Firmware < mslsg.081.233 - Improper Access Control
CVSS 7.5
CVE-2023-24058 MEDIUM
Booked Scheduler <2.5.5 - Privilege Escalation
CVSS 4.3
CVE-2023-24028 CRITICAL
MISP <2.4.167 - Privilege Escalation
CVSS 9.8
CVE-2023-22339 HIGH
CONPROSYS HMI System <3.4.5 - Auth Bypass
CVSS 7.5
CVE-2023-21860 MEDIUM
Oracle MySQL <7.4.38, <7.5.28, <7.6.24, <8.0.31 - Privilege Escalation
CVSS 6.3
CVE-2023-21894 HIGH
Oracle Fusion Middleware <13.9.4.2.11 - Privilege Escalation
CVSS 7.3
CVE-2023-21893 HIGH
Oracle Data Provider for .NET <21c - RCE
CVSS 7.5
CVE-2023-21857 HIGH
Oracle E-Business Suite <12.2.13 - RCE
CVSS 7.5
CVE-2023-21855 HIGH
Oracle Sales for Handhelds <12.2.12 - Unauthorized Access
CVSS 7.5
CVE-2023-21854 HIGH
Oracle E-Business Suite <12.2.13 - Unauthenticated RCE
CVSS 7.5
Details
Vulnerabilities 5,306