CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2023-21853 HIGH
Oracle Mobile Field Service <12.2.13 - Unauthorized Access
CVSS 7.5
CVE-2023-21852 HIGH
Oracle E-Business Suite - Unauthorized Access
CVSS 7.5
CVE-2023-21851 HIGH
Oracle E-Business Suite - Unauthorized Access
CVSS 7.5
CVE-2023-21850 HIGH
Oracle Demantra Demand Mgmt <12.2 - Info Disclosure
CVSS 7.5
CVE-2023-21849 HIGH
Oracle E-Business Suite <12.2.13 - RCE
CVSS 7.5
CVE-2023-21846 HIGH
Oracle BI Publisher <12.2.1.4.0 - Takeover
CVSS 8.8
CVE-2023-21832 HIGH
Oracle BI Publisher <12.2.1.4.0 - Takeover
CVSS 8.8
CVE-2023-21828 HIGH
Oracle Food and Beverage Apps <9.1.0 - Unauthorized Access
CVSS 8.1
CVE-2023-22600 CRITICAL
InRouter 302 < 3.5.56 and InRouter 615 < 2.3.0.r5542 - Unauthenticated MQTT Topic Subscription
CVSS 10.0
CVE-2023-22487 HIGH
Flarum < 1.6.3 - Unauthenticated Information Disclosure via Mentions Feature
CVSS 7.7
CVE-2023-21752 HIGH
Windows Backup Service - Privilege Escalation
CVSS 7.1
CVE-2023-21750 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.1
CVE-2023-21742 HIGH
Microsoft SharePoint Server - Remote Code Execution
CVSS 8.8
CVE-2023-21531 HIGH
Azure Service Fabric - Privilege Escalation
CVSS 7.0
CVE-2023-22903 CRITICAL
LibrePhotos < 2023-01-09 - Improper Access Control in User API
CVSS 9.8
CVE-2023-0017 CRITICAL
SAP NetWeaver AS for Java <7.50 - Privilege Escalation
CVSS 9.4
CVE-2023-0012 MEDIUM
SAP Host Agent (Windows) <7.22 - Privilege Escalation
CVSS 6.4
CVE-2023-22473 LOW
Nextcloud Talk < 15.0.2 - Improper Access Control via Passcode Bypass
CVSS 2.1
CVE-2022-31231 MEDIUM
Dell Ecs - Improper Access Control
CVSS 5.9
CVE-2022-43110 CRITICAL
Voltronic Power ViewPower <1.04-21353 & PowerShield Netguard <1.04-...
CVSS 9.8
CVE-2022-26389 HIGH
Baxter/Hillrom ELI 380 Resting Electrocardiograph < 2.6.0 - Privilege Escalation
CVSS 7.7
CVE-2022-45929 HIGH
Northern.tech Mender <3.3.2, <3.5.0, <3.6.0 - Privilege Escalation
CVSS 8.8
CVE-2022-41324 MEDIUM
Northern.tech Mender <3.3.2, <3.4.0 - Info Disclosure
CVSS 6.5
CVE-2022-23829 HIGH
AMD Ryzen Processors - Improper Access Control in SPI Protection Features
CVSS 8.2
CVE-2022-48683 HIGH
macOS < 13.0 - Sandbox Escape via Improper Access Control
CVSS 7.8
Details
Vulnerabilities 5,306