CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,306 vulnerabilities with CWE-284
CVE-2022-28173 CRITICAL
Hikvision DS-3WF0AC-2NT and DS-3WF01C-2N/O Firmware - Unauthenticated Privilege Escalation to Admin via Crafted Messages
CVSS 9.1
CVE-2022-4567 HIGH
GitHub openemr/openemr <7.0.0.2 - Info Disclosure
CVSS 8.1
CVE-2022-31708 MEDIUM
vRealize Operations 8.6.0-8.6.4.20823815 - Improper Access Control
CVSS 4.9
CVE-2022-25627 MEDIUM
Symantec Identity Manager 14.4 - Authenticated Remote Command Execution via Management Console
CVSS 6.7
CVE-2022-42865 MEDIUM
iPadOS < 16.2 - Privacy Preferences Bypass via Hardened Runtime
CVSS 5.5
CVE-2022-42862 MEDIUM
iPadOS < 16.2 - Privacy Preferences Bypass
CVSS 5.5
CVE-2022-42861 HIGH
iPadOS < 15.7.2 - Sandbox Escape via Improved Checks Bypass
CVSS 8.8
CVE-2022-42859 MEDIUM
iPadOS < 16.2 - Privacy Preference Bypass via Improper Access Control
CVSS 5.5
CVE-2022-42853 MEDIUM
macOS < 13.1 - Unprotected File System Modification via Improper Access Control
CVSS 5.5
CVE-2022-32945 MEDIUM
iPadOS < 16.0 - Unauthorized Audio Recording via Paired AirPods
CVSS 4.3
CVE-2022-47407 MEDIUM
Master-Quiz < 2.2.1 and 3.x < 3.5.1 - Unauthenticated Quiz Session Takeover
CVSS 6.5
CVE-2022-38355 HIGH
Daikin SVMPC1 <2.1.22 - Info Disclosure
CVSS 7.5
CVE-2022-46664 HIGH
Mendix Workflow Commons <V2.4.0, <V2.1.4, <V2.3.2 - Info Disclosure
CVSS 8.1
CVE-2022-46354 MEDIUM
SCALANCE X204RNA - Info Disclosure
CVSS 5.3
CVE-2022-45937 HIGH
Siemens APOGEE PXC and TALON TC Firmware - Authenticated Sensitive Information Exposure via Web Server
CVSS 8.8
CVE-2022-45936 HIGH
Mendix Email Connector < 2.0.0 - Authenticated Improper Access Control
CVSS 8.1
CVE-2022-41261 MEDIUM
SAP Solution Manager Diagnostic Agent <7.20 - Info Disclosure
CVSS 6.0
CVE-2022-23485 MEDIUM
Sentry 20.6.0-22.10.0 - Improper Access Control via Invite Link Cookie Manipulation
CVSS 6.4
CVE-2022-44932 HIGH
Tenda A18 v15.13.07.09 - Unauthenticated Telnet Service Access
CVSS 7.5
CVE-2022-39915 LOW
Samsung Calendar < 11.6.08.0 - Improper Access Control via Implicit Intent
CVSS 3.3
CVE-2022-39910 LOW
Samsung Pass < 4.0.06.7 - Unauthenticated Data Access via Pop-up View
CVSS 3.9
CVE-2022-39906 LOW
Android SecTelephonyProvider - Improper Access Control
CVSS 2.3
CVE-2022-39900 MEDIUM
Android Nice Catch - Unauthenticated Improper Access Control
CVSS 4.6
CVE-2022-39898 MEDIUM
Android - Improper Access Control in IIccPhoneBook
CVSS 4.0
CVE-2022-39896 MEDIUM
Android Contacts - Improper Access Control via Implicit Intent
CVSS 4.0
Details
Vulnerabilities 5,306