CWE-284
7,473 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,473)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nfine 1Nfine Rapid Development Platform Jun 17, 2026 May 25, 2023 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an unknown part of the file /SystemManage/Role/GetGridJson?keyword=&page=1&rows=20. The manipulation lea...Show more |
1Nfine Rapid Development Platform Project 1Nfine Rapid Development Platform Jun 17, 2026 May 25, 2023 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /SystemManage/Organize/GetTreeGridJson?_search=fa...Show more |
1Nfine Rapid Development Platform Project 1Nfine Rapid Development Platform Jun 17, 2026 May 25, 2023 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in NFine Rapid Development Platform 20230511. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /SystemManage/User/GetGridJson?_search=f...Show more |
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true. |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual i...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual ins...Show more |
Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. |
1Sick 7Ftmg Esd15axx Firmware Ftmg Esd20axx FirmwareFtmg Esd25axx Firmware+4 moreJun 17, 2026 May 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to download files by using a therefore unpriviled...Show more |
1Sick 7Ftmg Esd15axx Firmware Ftmg Esd20axx FirmwareFtmg Esd25axx Firmware+4 moreJun 17, 2026 May 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Access Control in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to gain unauthorized access to data fields by usi...Show more |
Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 64Server Board S1200btl Firmware Server Board S1200btlr FirmwareServer Board S1200btlrm Firmware+61 moreJun 17, 2026 May 12, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via...Show more |
1Intel 6Oneapi Ai Analytics Toolkit Oneapi Base ToolkitOneapi Dl Framework Developer Toolkit+3 moreJun 17, 2026 May 12, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. |
1Oretnom23 1Lost And Found Information System Jun 17, 2026 May 12, 2023 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/?page=user/manage_user. The manipulation lead...Show more |
1Rockwellautomation 1Kinetix 5500 Firmware Jun 17, 2026 May 11, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attacke...Show more |
1Canon 45I Sensys Lbp621cw Firmware I Sensys Lbp623cdw FirmwareI Sensys Lbp633cdw Firmware+42 moreJun 17, 2026 May 11, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C...Show more |
1Intel 59Compute Stick Stk2mv64cc Firmware Nuc 7 Enthusiast Nuc7i7bnhxg FirmwareNuc 7 Enthusiast Nuc7i7bnkq Firmware+56 moreJun 17, 2026 May 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access. |
Improper access control in the Intel(R) Unite(R) android application before Release 17 may allow a privileged user to potentially enable information disclosure via local access. |
1Intel 41Lapkc51e Firmware Lapkc71e FirmwareLapkc71f Firmware+38 moreJun 17, 2026 May 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. |
Improper access control in the Intel(R) Retail Edge android application before version 3.0.301126-RELEASE may allow an authenticated user to potentially enable information disclosure via local access. |