CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,309 vulnerabilities with CWE-284
CVE-2022-20918 HIGH
Cisco FirePOWER Software SNMP Info Disclosure via Default Credentials
CVSS 7.5
CVE-2022-25679 MEDIUM
Qualcomm Snapdragon Firmware - Denial of Service via Video Broadcast Receiver
CVSS 6.2
CVE-2022-42126 MEDIUM
Liferay Portal 7.3.5-7.4.3.28 and DXP 7.3-7.4 - Authenticated Improper Access Control in Asset Libraries
CVSS 4.3
CVE-2022-36789 HIGH
Intel NUC 10 Performance Kit and Mini PC Firmware < FNCML357.0053 - Authenticated Privilege Escalation via Local Access
CVSS 7.5
CVE-2022-35276 HIGH
Intel NUC 8 Compute Element Firmware < CBWHL357.0096 - Authenticated Privilege Escalation via Local Access
CVSS 7.5
CVE-2022-43679 MEDIUM
ownCloud Server <=10.11 - Info Disclosure
CVSS 4.2
CVE-2022-39889 MEDIUM
GalaxyWatch4Plugin < 2.2.11.22101351 - Improper Access Control
CVSS 4.0
CVE-2022-39887 MEDIUM
Android - Improper Access Control in MiscPolicy clearAllGlobalProxy
CVSS 4.3
CVE-2022-39884 MEDIUM
Android - Improper Access Control in IImsService
CVSS 4.3
CVE-2022-31687 CRITICAL
VMware Workspace ONE Assist < 22.10 - Unauthenticated Broken Access Control
CVSS 9.8
CVE-2022-27673 HIGH
AMD Link < 5.0.220614 - Information Disclosure via Insufficient Access Controls
CVSS 7.5
CVE-2022-25932 CRITICAL
InRouter302 Firmware < 3.5.56 - Privilege Escalation and Information Disclosure
CVSS 9.8
CVE-2022-42707 HIGH
Mahara 21.04.0-21.04.6, 21.10.0-21.10.4, 22.04.0-22.04.2 - Improper Access Control in Embedded Image Handling
CVSS 7.5
CVE-2022-22442 MEDIUM
IBM InfoSphere Information Server 11.7 - Privilege Escalation
CVSS 6.5
CVE-2022-39370 MEDIUM
GLPI 0.70-10.0.3 - Authenticated Improper Access Control via Update Script Debug Panel
CVSS 4.3
CVE-2022-44622 LOW
JetBrains TeamCity 2021.2-2022.10 - Improper Access Control for Secure Token Health Items
CVSS 2.7
CVE-2022-42814 MEDIUM
macOS < 13.0 - Unprotected User Data Exposure via Logic Issue
CVSS 5.5
CVE-2022-42811 MEDIUM
iPadOS < 16.0 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 5.5
CVE-2022-32946 MEDIUM
iPadOS < 16.0 - Unauthorized Audio Recording via AirPods
CVSS 5.5
CVE-2022-32918 MEDIUM
iPhone OS < 16.0 and macOS < 13.0 - Privacy Preference Bypass
CVSS 5.5
CVE-2022-32904 MEDIUM
macOS 11.0-11.6 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 5.5
CVE-2022-3780 HIGH
Remote Desktop Manager < 2022.3.8 - Unauthorized Data Access via Deleted User Database Connections
CVSS 7.5
CVE-2022-42327 HIGH
Xen - Unintended Memory Sharing Between Guests via xAPIC Page Access
CVSS 7.1
CVE-2022-39329 LOW
Nextcloud Server and Nextcloud Enterprise Server < 23.0.9 - Unauthenticated Information Exposure
CVSS 3.5
CVE-2022-33757 MEDIUM
Nessus < 10.2.0 - Authenticated Improper Access Control in Debug Log File Attachments
CVSS 6.5
Details
Vulnerabilities 5,309