CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,294 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 47 of 126
- CVE-2023-44290HIGHCVSS 7.8EG 7.82023-11-23
Dell Command | Monitor versions prior to 10.10.0, contain an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability while repairing/changing installation, leading to privilege e…
- CVE-2023-44292HIGHCVSS 7.8EG 7.82023-11-16
Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges.…
- CVE-2023-44794CRITICALCVSS 9.8EG 9.82023-10-25
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
- CVE-2023-45209MEDIUMCVSS 5.3EG 5.32024-04-17
An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An…
- CVE-2023-45210MEDIUMCVSS 4.3EG 4.32023-12-06
Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other users who are not permitted to access.
- CVE-2023-45217HIGHCVSS 8.8EG 8.82024-05-16
Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-45228MEDIUMCVSS 6.5EG 6.52023-10-26
The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.
- CVE-2023-4546MEDIUMCVSS 6.5EG 6.52023-08-26
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /sysmanage/licence.php. The manipulation leads t…
- CVE-2023-45744HIGHCVSS 8.3EG 8.32024-04-17
A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to configuration modification. An attacker can make an …
- CVE-2023-45844HIGHCVSS 6.8EG 7.32023-10-25
The vulnerability allows a low privileged user that have access to the device when locked in Kiosk mode to install an arbitrary Android application and leverage it to have access to critical device settings such as the device power managem…
- CVE-2023-46033MEDIUMCVSS 6.8EG 6.82023-10-19
D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the PCB, provides log output and a root terminal without proper access control.
- CVE-2023-4640HIGHCVSS 7.5EG 7.52023-08-30
The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes …
- CVE-2023-4650MEDIUMCVSS 4.7EG 4.72023-08-31
Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- CVE-2023-46501CRITICALCVSS 9.1EG 9.12023-11-07
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.
- CVE-2023-4658LOWCVSS 3.1EG 3.12023-12-01
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `…
- CVE-2023-46601CRITICALCVSS 7.5EG 9.62023-11-14
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that t…
- CVE-2023-46661CRITICALCVSS 9.8EG 9.82023-10-26
Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.
- CVE-2023-46662HIGHCVSS 7.5EG 7.52023-10-26
Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this via a specially crafted request to gain access to sensitive in…
- CVE-2023-46663HIGHCVSS 8.1EG 8.12023-10-26
Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without performing any val…
- CVE-2023-46664CRITICALCVSS 9.1EG 9.12023-10-26
Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authoriza…
- CVE-2023-46665CRITICALCVSS 9.8EG 9.82023-10-26
Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges. …
- CVE-2023-46666MEDIUMCVSS 6.5EG 6.52023-10-26
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that…
- CVE-2023-46712HIGHCVSS 7.2EG 7.22024-01-10
A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
- CVE-2023-46755MEDIUMCVSS 5.3EG 5.32023-11-08
Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.
- CVE-2023-46759HIGHCVSS 7.5EG 7.52023-11-08
Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-4696CRITICALCVSS 9.8EG 9.82023-09-01
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
- CVE-2023-46992HIGHCVSS 7.5EG 7.52023-10-31
TOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords without authentication by visiting specific pages.
- CVE-2023-4700MEDIUMCVSS 6.5EG 6.52023-11-06
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.
- CVE-2023-47031CRITICALCVSS 9.8EG 9.82025-06-23
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRolesToGroups, and grantRolesToOrganization SOAP API component.
- CVE-2023-47034HIGHCVSS 7.5EG 7.52024-01-19
A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.
- CVE-2023-47110MEDIUMCVSS 5.3EG 5.32023-11-09
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This…
- CVE-2023-47294HIGHCVSS 8.1EG 8.12025-06-23
An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts via a crafted session cookie.
- CVE-2023-47297CRITICALCVSS 9.8EG 9.82025-06-23
A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system security auditing configurations.
- CVE-2023-47325MEDIUMCVSS 5.4EG 5.42023-12-13
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the …
- CVE-2023-47422HIGHCVSS 8.8EG 8.82024-02-20
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
- CVE-2023-47536MEDIUMCVSS 5.3EG 5.32023-12-13
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote un…
- CVE-2023-47539CRITICALCVSS 9.8EG 9.82025-03-18
An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request.
- CVE-2023-47579HIGHCVSS 7.5EG 7.52023-12-13
Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.
- CVE-2023-47678CRITICALCVSS 9.1EG 9.12023-11-15
An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp.
- CVE-2023-47858MEDIUMCVSS 4.3EG 4.32024-01-02
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channe…
- CVE-2023-47859MEDIUMCVSS 5.5EG 5.52024-05-16
Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2023-47865MEDIUMCVSS 4.3EG 4.32023-11-27
Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also overrid…
- CVE-2023-47867HIGHCVSS 8.8EG 8.82024-02-01
MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device.
- CVE-2023-4812HIGHCVSS 7.6EG 7.62024-01-12
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypa…
- CVE-2023-48239HIGHCVSS 7.1EG 7.12023-11-21
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and starting in version 20.0.0 and prior to versions 20.0…
- CVE-2023-48303LOWCVSS 2.7EG 2.72023-11-21
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and Nextcloud Enterprise Server, admins can change authen…
- CVE-2023-48441MEDIUMCVSS 5.3EG 5.32023-12-15
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application. Exploitation of th…
- CVE-2023-4895MEDIUMCVSS 4.3EG 4.32024-02-22
An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. This vulnerability allows for bypassing the 'group…
- CVE-2023-49098LOWCVSS 3.5EG 3.52024-01-12
Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability was patched in commit 2c26939.
- CVE-2023-49099LOWCVSS 3.1EG 3.12024-01-12
Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when login is required. This vulnerability has been patched in 3.2.0.beta4 an…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →