CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,306 vulnerabilities with CWE-284
CVE-2023-25161
LOW
Nextcloud Server < 23.0.12, 24.0.8, 25.0.1 - Denial of Service via Password Reset Rate Limit Bypass
CVSS 3.7
CVE-2023-25159
LOW
Nextcloud Server 24.0.4-24.0.7 and 25.0.0 - Improper Access Control in Preview Watermark
CVSS 2.3
CVE-2023-0661
MEDIUM
Devolutions Server 2022.3.1.0-2022.3.10.0 - Authenticated Improper Access Control
CVSS 6.5
CVE-2023-24688
MEDIUM
mojoportal 2.7.0.0 - Unauthenticated User Registration Bypass
CVSS 5.3
CVE-2023-21447
MEDIUM
Samsung Cloud < 5.3.0.32 - Improper Access Control via Implicit Intent
CVSS 4.0
CVE-2023-21445
MEDIUM
Samsung Android MyFiles < 12.2.09/13.1.03.501/14.1.00.422 - Unauthenticated Arbitrary File Write via Implicit Intent
CVSS 5.5
CVE-2023-21442
MEDIUM
Samsung Android Runestone < 2.9.09.003 (R) and < 3.2.01.007 (S) - Unauthenticated Device Location Information Disclosure
CVSS 4.0
CVE-2023-21438
LOW
Samsung Android - Improper Access Control in HomeScreen
CVSS 2.1
CVE-2023-21427
MEDIUM
Samsung Android - Improper Access Control in NfcTile
CVSS 5.4
CVE-2023-25150
MEDIUM
Nextcloud richdocuments < 3.8.7 - Improper Access Control via Collabora Integration
CVSS 5.8
CVE-2023-0744
CRITICAL
answerdev/answer < 1.0.4 - Account Takeover via Improper Access Control
CVSS 9.8
CVE-2023-23615
MEDIUM
Discourse < 3.0.0 - Unauthenticated Topic Creation via Embeddable Comments
CVSS 5.3
CVE-2023-24425
MEDIUM
Jenkins Kubernetes Credentials Provider Plugin <1.208 - Privilege E...
CVSS 6.5
CVE-2023-24022
CRITICAL
Baicells Nova - Hardcoded Credentials
CVSS 10.0
CVE-2023-0451
HIGH
Econolite EOS < 3.2.23 - Unauthenticated Sensitive Information Exposure via Log and Configuration Files
CVSS 7.5
CVE-2023-22960
HIGH
Lexmark B2236 Firmware < mslsg.081.233 - Improper Access Control
CVSS 7.5
CVE-2023-24058
MEDIUM
Booked Scheduler <2.5.5 - Privilege Escalation
CVSS 4.3
CVE-2023-24028
CRITICAL
MISP <2.4.167 - Privilege Escalation
CVSS 9.8
CVE-2023-22339
HIGH
CONPROSYS HMI System <3.4.5 - Auth Bypass
CVSS 7.5
CVE-2023-21860
MEDIUM
Oracle MySQL <7.4.38, <7.5.28, <7.6.24, <8.0.31 - Privilege Escalation
CVSS 6.3
CVE-2023-21894
HIGH
Oracle Fusion Middleware <13.9.4.2.11 - Privilege Escalation
CVSS 7.3
CVE-2023-21893
HIGH
Oracle Data Provider for .NET <21c - RCE
CVSS 7.5
CVE-2023-21857
HIGH
Oracle E-Business Suite <12.2.13 - RCE
CVSS 7.5
CVE-2023-21855
HIGH
Oracle Sales for Handhelds <12.2.12 - Unauthorized Access
CVSS 7.5
CVE-2023-21854
HIGH
Oracle E-Business Suite <12.2.13 - Unauthenticated RCE
CVSS 7.5
Details
Vulnerabilities
5,306