CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,309 vulnerabilities with CWE-284
CVE-2022-39900 MEDIUM
Android Nice Catch - Unauthenticated Improper Access Control
CVSS 4.6
CVE-2022-39898 MEDIUM
Android - Improper Access Control in IIccPhoneBook
CVSS 4.0
CVE-2022-39896 MEDIUM
Android Contacts - Improper Access Control via Implicit Intent
CVSS 4.0
CVE-2022-39895 MEDIUM
Android Phone - Improper Access Control in ContactListUtils via Implicit Intent
CVSS 4.0
CVE-2022-39894 MEDIUM
Android Phone - Improper Access Control in ContactListStartActivityHelper via Implicit Intent
CVSS 4.0
CVE-2022-37918 HIGH
Aruba AirWave < 8.2.15.0 - Improper Access Control in Web Management Interface
CVSS 8.1
CVE-2022-37917 HIGH
Aruba AirWave < 8.2.15.0 - Improper Access Control in Web Management Interface
CVSS 8.1
CVE-2022-37916 HIGH
Aruba AirWave < 8.2.15.0 - Improper Access Control in Web Management Interface
CVSS 8.1
CVE-2022-35843 HIGH
FortiOS/FortiProxy <7.2.0,6.4.9,6.2,6.0 - Auth Bypass
CVSS 8.1
CVE-2022-44212 MEDIUM
GL.iNet Goodcloud 1.0 - Info Disclosure
CVSS 5.9
CVE-2022-44211 HIGH
GL.iNet Goodcloud 1.1 - Info Disclosure
CVSS 7.4
CVE-2022-41970 LOW
Nextcloud Server < 24.0.7 and 25.0.1 - Improper Access Control via Preview Image Download
CVSS 2.6
CVE-2022-4229 HIGH
Book Store Management System 1.0 - Improper Access Control in /bsms_ci/index.php
CVSS 7.3
CVE-2022-44037 HIGH
APsystems ENERGY COMMUNICATION UNIT - Info Disclosure
CVSS 8.8
CVE-2022-45475 MEDIUM
Tiny File Manager 2.4.8 - Unauthenticated Improper Access Control
CVSS 6.5
CVE-2022-38377 MEDIUM
FortiManager/FortiAnalyzer <7.2.0 - Privilege Escalation
CVSS 4.3
CVE-2022-39070 CRITICAL
ZTE ZXA10 C350M and C300M Firmware 2.1.0-2.1.0xgp002.4 - Unauthenticated Remote Command Execution
CVSS 9.8
CVE-2022-4087 LOW
iPXE < 2022-11-08 - Information Exposure via TLS Ciphertext Padding Length
CVSS 2.6
CVE-2022-41155 MEDIUM
WordPress iQ Block Country <1.2.18 - Auth Bypass
CVSS 5.3
CVE-2022-41135 MEDIUM
WordPress Modula <2.6.9 - Info Disclosure
CVSS 6.5
CVE-2022-40216 MEDIUM
Better Messages <= 1.9.10.69 - Authenticated Messaging Block Bypass
CVSS 4.3
CVE-2022-34827 CRITICAL
Carel Boss Mini 1.5.0 - Improper Access Control
CVSS 9.9
CVE-2022-41652 MEDIUM
Quiz And Survey Master <7.3.10 - Auth Bypass
CVSS 6.5
CVE-2022-24038 MEDIUM
Karmasis Informatics Infraskope SIEM+ - Info Disclosure
CVSS 6.5
CVE-2022-24036 HIGH
Karmasis Informatics Infraskope SIEM+ - Info Disclosure
CVSS 8.6
Details
Vulnerabilities 5,309