CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,294 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 44 of 126
- CVE-2023-34316MEDIUMCVSS 6.5EG 6.52023-07-10
An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior to 1.0.7) patch, which could allow an attacker to retrieve file contents.
- CVE-2023-34403MEDIUMCVSS 4.9EG 4.92025-02-13
Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to internal network. A race condition can be acquired and attacker can spoof “UserData” with desirable…
- CVE-2023-34404MEDIUMCVSS 4.9EG 4.92025-02-13
Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to these pins and get access to internal network. As a result, by accessing a specific port an attacker can send call request to all r…
- CVE-2023-3443LOWCVSS 3.1EG 3.12023-12-01
An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji …
- CVE-2023-34469MEDIUMCVSS 4.9EG 4.92023-09-12
AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the physical network. A successful exploit of this vulnerability may lead to a loss of confidentiality.
- CVE-2023-34470MEDIUMCVSS 6.8EG 6.82023-09-12
AMI AptioV contains a vulnerability in BIOS where an Attacker may use an improper access control via the local network. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity and availability.
- CVE-2023-35062MEDIUMCVSS 6.3EG 6.72024-02-14
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-3509LOWCVSS 3.7EG 3.72024-02-21
An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change…
- CVE-2023-3511LOWCVSS 2.0EG 2.02023-12-15
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and …
- CVE-2023-35121HIGHCVSS 7.8EG 7.82024-02-14
Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local acces…
- CVE-2023-35167MEDIUMCVSS 5.0EG 5.02023-06-23
Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unauthorized access to data, an attacker who knows the `i…
- CVE-2023-35173MEDIUMCVSS 5.7EG 5.72023-06-23
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommende…
- CVE-2023-35179HIGHCVSS 7.2EG 7.22023-08-11
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action.
- CVE-2023-35870MEDIUMCVSS 6.3EG 6.32023-07-11
When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and i…
- CVE-2023-35927HIGHCVSS 7.6EG 7.62023-06-23
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.…
- CVE-2023-35939HIGHCVSS 8.1EG 8.12023-07-05
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a on a file accessible by an authenticated user (or not for certain actions), allows a threat acto…
- CVE-2023-35940HIGHCVSS 7.5EG 7.52023-07-05
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contain…
- CVE-2023-36106HIGHCVSS 7.5EG 7.52023-08-17
An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.
- CVE-2023-3622MEDIUMCVSS 4.3EG 4.62023-07-26
Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource
- CVE-2023-36404MEDIUMCVSS 5.5EG 5.52023-11-14
Windows Kernel Information Disclosure Vulnerability
- CVE-2023-36465CRITICALCVSS 9.1EG 9.12023-10-06
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allo…
- CVE-2023-36497HIGHCVSS 8.8EG 8.82023-09-11
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 could allow a guest user to elevate to admin privileges.
- CVE-2023-36538HIGHCVSS 8.4EG 8.42023-07-11
Improper access control in Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
- CVE-2023-36554HIGHCVSS 8.1EG 8.12024-03-12
A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specia…
- CVE-2023-36561HIGHCVSS 7.3EG 7.32023-10-10
Azure DevOps Server Elevation of Privilege Vulnerability
- CVE-2023-36620MEDIUMCVSS 4.6EG 4.62023-11-03
An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal memory of the app to …
- CVE-2023-36635HIGHCVSS 7.1EG 7.12023-09-07
An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API.
- CVE-2023-36638MEDIUMCVSS 4.3EG 4.32023-09-13
An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 t…
- CVE-2023-3664HIGHCVSS 7.2EG 7.22023-09-25
The FileOrganizer WordPress plugin through 1.0.2 does not restrict functionality on multisite instances, allowing site admins to gain full control over the server.
- CVE-2023-36643HIGHCVSS 7.5EG 7.52024-04-04
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.
- CVE-2023-36644HIGHCVSS 7.5EG 7.52024-04-04
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.
- CVE-2023-36722MEDIUMCVSS 4.4EG 4.42023-10-10
Active Directory Domain Services Information Disclosure Vulnerability
- CVE-2023-36725HIGHCVSS 7.8EG 7.82023-10-10
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-36790HIGHCVSS 7.8EG 7.82023-10-10
Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
- CVE-2023-36820MEDIUMCVSS 4.8EG 4.82023-10-09
Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same…
- CVE-2023-36889MEDIUMCVSS 5.5EG 5.52023-08-08
Windows Group Policy Security Feature Bypass Vulnerability
- CVE-2023-36890MEDIUMCVSS 6.5EG 6.52023-08-08
Microsoft SharePoint Server Information Disclosure Vulnerability
- CVE-2023-37194MEDIUMCVSS 6.7EG 6.72023-10-10
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). The kernel memory of affected devices is…
- CVE-2023-37234CRITICALCVSS 9.8EG 9.82024-09-10
Loftware Spectrum through 4.6 has unprotected JMX Registry.
- CVE-2023-37267HIGHCVSS 7.5EG 7.52023-07-13
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.
- CVE-2023-37478HIGHCVSS 7.5EG 7.52023-08-01
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package th…
- CVE-2023-37483CRITICALCVSS 9.8EG 9.82023-08-08
SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.
- CVE-2023-37749MEDIUMCVSS 5.3EG 5.32025-10-27
Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.
- CVE-2023-37759CRITICALCVSS 9.8EG 9.82023-09-08
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.
- CVE-2023-3786MEDIUMCVSS 4.3EG 4.32023-07-20
A vulnerability classified as problematic has been found in Aures Komet up to 20230509. This affects an unknown part of the component Kiosk Mode. The manipulation leads to improper access controls. It is possible to launch the attack on th…
- CVE-2023-38005MEDIUMCVSS 4.3EG 4.32026-02-17
IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could allow an authenticated user to perform unauthorized tasks due to improper access controls.
- CVE-2023-38132HIGHCVSS 8.8EG 8.82023-08-18
LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows an unauthenticated attacker to log in to telnet service.
- CVE-2023-3814MEDIUMCVSS 4.9EG 4.92023-09-04
The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server.
- CVE-2023-38167HIGHCVSS 7.2EG 7.22023-08-08
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
- CVE-2023-38205CRITICALCVSS 7.5EG 9.0⚠ KEV2023-09-14
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnera…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →