Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2022-12-28 CVE-2022-4814 Improper Access Control vulnerability in Usememos Memos
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
network
low complexity
usememos CWE-284
4.3
2022-12-27 CVE-2022-4724 Improper Access Control vulnerability in Ikus-Soft Rdiffweb
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
network
low complexity
ikus-soft CWE-284
critical
9.8
2022-12-23 CVE-2022-4684 Improper Access Control vulnerability in Usememos Memos
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
network
low complexity
usememos CWE-284
8.8
2022-12-23 CVE-2022-4689 Improper Access Control vulnerability in Usememos Memos
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
network
low complexity
usememos CWE-284
8.8
2022-12-23 CVE-2022-23513 Improper Access Control vulnerability in Pi-Hole Adminlte 5.12/5.13
Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more.
network
low complexity
pi-hole CWE-284
5.3
2022-12-22 CVE-2022-41654 Improper Access Control vulnerability in Ghost
An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4.
network
low complexity
ghost CWE-284
4.3
2022-12-17 CVE-2022-4567 Improper Access Control vulnerability in Open-Emr Openemr
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.
network
low complexity
open-emr CWE-284
8.1
2022-12-13 CVE-2022-46664 Improper Access Control vulnerability in Siemens Mendix Workflow Commons
A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix Workflow Commons V2.3 (All versions < V2.3.2).
network
low complexity
siemens CWE-284
8.1
2022-11-18 CVE-2022-24038 Improper Access Control vulnerability in Karmasis Infraskope Siem+
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed.
network
low complexity
karmasis CWE-284
6.5
2022-11-16 CVE-2022-24036 Improper Access Control vulnerability in Karmasis Infraskope Siem+
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs.
network
low complexity
karmasis CWE-284
8.6