CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,306 vulnerabilities with CWE-284
CVE-2022-28173
CRITICAL
Hikvision DS-3WF0AC-2NT and DS-3WF01C-2N/O Firmware - Unauthenticated Privilege Escalation to Admin via Crafted Messages
CVSS 9.1
CVE-2022-4567
HIGH
GitHub openemr/openemr <7.0.0.2 - Info Disclosure
CVSS 8.1
CVE-2022-31708
MEDIUM
vRealize Operations 8.6.0-8.6.4.20823815 - Improper Access Control
CVSS 4.9
CVE-2022-25627
MEDIUM
Symantec Identity Manager 14.4 - Authenticated Remote Command Execution via Management Console
CVSS 6.7
CVE-2022-42865
MEDIUM
iPadOS < 16.2 - Privacy Preferences Bypass via Hardened Runtime
CVSS 5.5
CVE-2022-42862
MEDIUM
iPadOS < 16.2 - Privacy Preferences Bypass
CVSS 5.5
CVE-2022-42861
HIGH
iPadOS < 15.7.2 - Sandbox Escape via Improved Checks Bypass
CVSS 8.8
CVE-2022-42859
MEDIUM
iPadOS < 16.2 - Privacy Preference Bypass via Improper Access Control
CVSS 5.5
CVE-2022-42853
MEDIUM
macOS < 13.1 - Unprotected File System Modification via Improper Access Control
CVSS 5.5
CVE-2022-32945
MEDIUM
iPadOS < 16.0 - Unauthorized Audio Recording via Paired AirPods
CVSS 4.3
CVE-2022-47407
MEDIUM
Master-Quiz < 2.2.1 and 3.x < 3.5.1 - Unauthenticated Quiz Session Takeover
CVSS 6.5
CVE-2022-38355
HIGH
Daikin SVMPC1 <2.1.22 - Info Disclosure
CVSS 7.5
CVE-2022-46664
HIGH
Mendix Workflow Commons <V2.4.0, <V2.1.4, <V2.3.2 - Info Disclosure
CVSS 8.1
CVE-2022-46354
MEDIUM
SCALANCE X204RNA - Info Disclosure
CVSS 5.3
CVE-2022-45937
HIGH
Siemens APOGEE PXC and TALON TC Firmware - Authenticated Sensitive Information Exposure via Web Server
CVSS 8.8
CVE-2022-45936
HIGH
Mendix Email Connector < 2.0.0 - Authenticated Improper Access Control
CVSS 8.1
CVE-2022-41261
MEDIUM
SAP Solution Manager Diagnostic Agent <7.20 - Info Disclosure
CVSS 6.0
CVE-2022-23485
MEDIUM
Sentry 20.6.0-22.10.0 - Improper Access Control via Invite Link Cookie Manipulation
CVSS 6.4
CVE-2022-44932
HIGH
Tenda A18 v15.13.07.09 - Unauthenticated Telnet Service Access
CVSS 7.5
CVE-2022-39915
LOW
Samsung Calendar < 11.6.08.0 - Improper Access Control via Implicit Intent
CVSS 3.3
CVE-2022-39910
LOW
Samsung Pass < 4.0.06.7 - Unauthenticated Data Access via Pop-up View
CVSS 3.9
CVE-2022-39906
LOW
Android SecTelephonyProvider - Improper Access Control
CVSS 2.3
CVE-2022-39900
MEDIUM
Android Nice Catch - Unauthenticated Improper Access Control
CVSS 4.6
CVE-2022-39898
MEDIUM
Android - Improper Access Control in IIccPhoneBook
CVSS 4.0
CVE-2022-39896
MEDIUM
Android Contacts - Improper Access Control via Implicit Intent
CVSS 4.0
Details
Vulnerabilities
5,306