CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,309 vulnerabilities with CWE-284
CVE-2022-20918
HIGH
Cisco FirePOWER Software SNMP Info Disclosure via Default Credentials
CVSS 7.5
CVE-2022-25679
MEDIUM
Qualcomm Snapdragon Firmware - Denial of Service via Video Broadcast Receiver
CVSS 6.2
CVE-2022-42126
MEDIUM
Liferay Portal 7.3.5-7.4.3.28 and DXP 7.3-7.4 - Authenticated Improper Access Control in Asset Libraries
CVSS 4.3
CVE-2022-36789
HIGH
Intel NUC 10 Performance Kit and Mini PC Firmware < FNCML357.0053 - Authenticated Privilege Escalation via Local Access
CVSS 7.5
CVE-2022-35276
HIGH
Intel NUC 8 Compute Element Firmware < CBWHL357.0096 - Authenticated Privilege Escalation via Local Access
CVSS 7.5
CVE-2022-43679
MEDIUM
ownCloud Server <=10.11 - Info Disclosure
CVSS 4.2
CVE-2022-39889
MEDIUM
GalaxyWatch4Plugin < 2.2.11.22101351 - Improper Access Control
CVSS 4.0
CVE-2022-39887
MEDIUM
Android - Improper Access Control in MiscPolicy clearAllGlobalProxy
CVSS 4.3
CVE-2022-39884
MEDIUM
Android - Improper Access Control in IImsService
CVSS 4.3
CVE-2022-31687
CRITICAL
VMware Workspace ONE Assist < 22.10 - Unauthenticated Broken Access Control
CVSS 9.8
CVE-2022-27673
HIGH
AMD Link < 5.0.220614 - Information Disclosure via Insufficient Access Controls
CVSS 7.5
CVE-2022-25932
CRITICAL
InRouter302 Firmware < 3.5.56 - Privilege Escalation and Information Disclosure
CVSS 9.8
CVE-2022-42707
HIGH
Mahara 21.04.0-21.04.6, 21.10.0-21.10.4, 22.04.0-22.04.2 - Improper Access Control in Embedded Image Handling
CVSS 7.5
CVE-2022-22442
MEDIUM
IBM InfoSphere Information Server 11.7 - Privilege Escalation
CVSS 6.5
CVE-2022-39370
MEDIUM
GLPI 0.70-10.0.3 - Authenticated Improper Access Control via Update Script Debug Panel
CVSS 4.3
CVE-2022-44622
LOW
JetBrains TeamCity 2021.2-2022.10 - Improper Access Control for Secure Token Health Items
CVSS 2.7
CVE-2022-42814
MEDIUM
macOS < 13.0 - Unprotected User Data Exposure via Logic Issue
CVSS 5.5
CVE-2022-42811
MEDIUM
iPadOS < 16.0 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 5.5
CVE-2022-32946
MEDIUM
iPadOS < 16.0 - Unauthorized Audio Recording via AirPods
CVSS 5.5
CVE-2022-32918
MEDIUM
iPhone OS < 16.0 and macOS < 13.0 - Privacy Preference Bypass
CVSS 5.5
CVE-2022-32904
MEDIUM
macOS 11.0-11.6 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 5.5
CVE-2022-3780
HIGH
Remote Desktop Manager < 2022.3.8 - Unauthorized Data Access via Deleted User Database Connections
CVSS 7.5
CVE-2022-42327
HIGH
Xen - Unintended Memory Sharing Between Guests via xAPIC Page Access
CVSS 7.1
CVE-2022-39329
LOW
Nextcloud Server and Nextcloud Enterprise Server < 23.0.9 - Unauthenticated Information Exposure
CVSS 3.5
CVE-2022-33757
MEDIUM
Nessus < 10.2.0 - Authenticated Improper Access Control in Debug Log File Attachments
CVSS 6.5
Details
Vulnerabilities
5,309