CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,309 vulnerabilities with CWE-284
CVE-2022-27805 CRITICAL
Abode Systems iota All-In-One Security Kit 6.9X and 6.9Z - Unauthenticated Arbitrary XCMD Execution via GHOME Control
CVSS 9.8
CVE-2022-26423 HIGH
Aethon TUG Home Base Server <24 - Info Disclosure
CVSS 8.2
CVE-2022-1066 HIGH
Aethon TUG Home Base Server < 24 - Unauthenticated Access to Hashed User Credentials
CVSS 8.2
CVE-2022-23241 HIGH
Clustered Data ONTAP 9.11.1-9.11.1P2 - Authenticated WORM Data Modification and Deletion
CVSS 8.1
CVE-2022-43429 HIGH
Jenkins Compuware Topaz for Total Test Plugin <2.4.8 - Info Disclosure
CVSS 7.5
CVE-2022-40798 HIGH
OcoMon < 4.0 - Unauthenticated Account Takeover via Email Enumeration
CVSS 7.5
CVE-2022-39421 HIGH
Oracle VM VirtualBox < 6.1.40 - Authenticated Remote Code Execution
CVSS 7.3
CVE-2022-39406 HIGH
Oracle PeopleSoft Enterprise Common Components 9.2 - Authenticated Improper Access Control in Approval Framework
CVSS 8.1
CVE-2022-39405 MEDIUM
Oracle Access Manager 12.2.1.3.0 - Unauthenticated Improper Access Control
CVSS 5.3
CVE-2022-39399 LOW
Oracle GraalVM 20.3.7, 21.3.3, 22.2.0 - Unauthenticated Data Manipulation via HTTP
CVSS 3.7
CVE-2022-21619 LOW
Oracle GraalVM & Java SE Multiple Versions - Unauthenticated Data Manipulation
CVSS 3.7
CVE-2022-38743 HIGH
Rockwell Automation FactoryTalk VantagePoint <8.31 - Privilege Esca...
CVSS 8.8
CVE-2022-3382 HIGH
HIWIN Robot System Software <3.3.21.9869 - DoS
CVSS 7.5
CVE-2022-3325 LOW
GitLab CE/EE <15.2.5-<15.3.4-<15.4.1 - Info Disclosure
CVSS 2.7
CVE-2022-3286 MEDIUM
GitLab EE <15.2.5-15.4.1 - Auth Bypass
CVSS 5.3
CVE-2022-3067 MEDIUM
GitLab CE/EE <15.2.5-15.4.1 - Info Disclosure
CVSS 6.5
CVE-2022-3066 MEDIUM
GitLab <15.2.5-15.4.1 - Info Disclosure
CVSS 5.4
CVE-2022-3030 MEDIUM
GitLab CE/EE <15.1.6, <15.2.4, <15.3.2 - Info Disclosure
CVSS 4.3
CVE-2022-2630 MEDIUM
GitLab CE/EE <15.2.4-15.3.2 - Info Disclosure
CVSS 4.3
CVE-2022-2052 CRITICAL
Trumpf Job Order Interface OSEON and TruTops Products - Unauthenticated Remote Access via Default Privileged Accounts
CVSS 9.8
CVE-2022-39310 MEDIUM
GoCD < 21.1.0 - Authenticated Agent Impersonation via Broken Access Control
CVSS 4.9
CVE-2022-35689 MEDIUM
Adobe Commerce <2.4.4-p1, 2.4.5 - Auth Bypass
CVSS 5.3
CVE-2022-28761 MEDIUM
Zoom On-Premise Meeting Connector MMR <4.8.20220916.131 - Privilege...
CVSS 6.5
CVE-2022-28760 MEDIUM
Zoom On-Premise Meeting Connector MMR <4.8.20220815.130 - Info Disc...
CVSS 6.5
CVE-2022-28759 HIGH
Zoom On-Premise Meeting Connector MMR <4.8.20220815.130 - Info Disc...
CVSS 8.2
Details
Vulnerabilities 5,309