CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 29 of 126
- CVE-2021-44460HIGHCVSS 6.5EG 7.42023-04-25
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deactivated accounts to access the system with the deactivated account and any permission it still holds, via crafted RPC req…
- CVE-2021-44465MEDIUMCVSS 4.3EG 5.32023-04-25
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated attackers to subscribe to receive future notifications and comments related to arbitrary business records in the system, v…
- CVE-2021-44467HIGHCVSS 5.3EG 7.52022-10-24
A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrarily terminate active sessions of other users, causing a Denial-of-Service (DoS) condition, if an input parameter is corr…
- CVE-2021-4477CRITICALCVSS 9.1EG 9.12026-04-03
Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall rules. Attackers can exploit this vulnerability by estab…
- CVE-2021-44776MEDIUMCVSS 6.5EG 6.52022-10-24
A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbitrarily change the security access rights to KVM and Virtual Media functionalities. This issue affects: Lanner Inc IAC-A…
- CVE-2021-45034HIGHCVSS 7.5EG 7.52022-01-11
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODU…
- CVE-2021-45074MEDIUMCVSS 4.3EG 5.42022-03-02
JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.
- CVE-2021-45111HIGHCVSS 8.1EG 8.12023-04-25
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, including user accounts with known credentials.
- CVE-2021-45730MEDIUMCVSS 6.0EG 6.02022-05-19
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrat…
- CVE-2021-46270LOWCVSS 2.7EG 2.72022-03-02
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.
- CVE-2021-46304HIGHCVSS 7.5EG 7.52022-08-10
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions), CP-8021 MASTER MODULE (All versions), CP-8022 MASTER MODULE WITH GPRS (All versions)…
- CVE-2021-46851CRITICALCVSS 9.8EG 9.82022-11-09
The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.
- CVE-2021-46903MEDIUMCVSS 6.5EG 6.52024-02-04
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can delete required user accounts (in violation of expected access control).
- CVE-2021-47155CRITICALCVSS 9.1EG 9.12024-03-18
The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
- CVE-2022-0133HIGHCVSS 7.5EG 7.52022-01-10
peertube is vulnerable to Improper Access Control
- CVE-2022-0143CRITICALCVSS 9.3EG 9.82022-09-19
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remo…
- CVE-2022-0170MEDIUMCVSS 4.3EG 4.32022-01-11
peertube is vulnerable to Improper Access Control
- CVE-2022-0203MEDIUMCVSS 5.3EG 5.32022-01-26
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.
- CVE-2022-0270HIGHCVSS 8.8EG 8.82022-01-25
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.
- CVE-2022-0273MEDIUMCVSS 6.5EG 6.52022-01-30
Improper Access Control in Pypi calibreweb prior to 0.6.16.
- CVE-2022-0405MEDIUMCVSS 4.3EG 4.32022-04-03
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
- CVE-2022-0541CRITICALCVSS 9.8EG 9.82022-04-25
The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.
- CVE-2022-0574MEDIUMCVSS 6.5EG 6.52022-05-16
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
- CVE-2022-0634MEDIUMCVSS 4.3EG 4.32022-04-25
The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, allowing a low-privilege user (with a role as low as Subscriber) to add an image from an external URL to an affiliate l…
- CVE-2022-0727MEDIUMCVSS 5.4EG 5.42022-02-23
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
- CVE-2022-0731MEDIUMCVSS 6.5EG 6.52022-02-23
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
- CVE-2022-0732HIGHCVSS 7.5EG 7.52022-02-24
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
- CVE-2022-0755MEDIUMCVSS 4.3EG 4.32022-03-07
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
- CVE-2022-0815HIGHCVSS 6.5EG 7.32022-03-10
Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could le…
- CVE-2022-0824CRITICALCVSS 8.8EG 9.02022-03-02
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
- CVE-2022-1025HIGHCVSS 8.8EG 8.82022-07-12
All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
- CVE-2022-1066HIGHCVSS 8.2EG 8.22022-10-21
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
- CVE-2022-1223MEDIUMCVSS 6.5EG 6.52022-04-04
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
- CVE-2022-1261HIGHCVSS 5.8EG 8.82022-05-26
Matrikon, a subsidary of Honeywell Matrikon OPC Server (all versions) is vulnerable to a condition where a low privileged user allowed to connect to the OPC server to use the functions of the IPersisFile to execute operating system process…
- CVE-2022-1316HIGHCVSS 8.8EG 8.82022-04-11
Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation
- CVE-2022-1323MEDIUMCVSS 6.5EG 6.52022-08-08
The Discy WordPress theme before 5.0 lacks authorization checks then processing ajax requests to the discy_update_options action, allowing any logged in users (with privileges as low as Subscriber,) to change Theme options by sending a cr…
- CVE-2022-1521CRITICALCVSS 9.1EG 9.12022-06-24
LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or intercept sensitive data.
- CVE-2022-1553MEDIUMCVSS 4.9EG 4.92022-05-16
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the…
- CVE-2022-1598MEDIUMCVSS 5.3EG 5.32022-06-08
The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unauthenticated users to discover private questions sent between users on the site.
- CVE-2022-1631HIGHCVSS 8.8EG 8.82022-05-09
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application …
- CVE-2022-1656MEDIUMCVSS 5.4EG 5.42022-06-13
Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to access any of the functions registered in lib/api/api/ajax.php, which also grant access to the jupiterx_api_ajax_ actions re…
- CVE-2022-1658MEDIUMCVSS 5.4EG 5.42022-06-13
Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, including users with the subscriber role, via the abb_remove_plugin AJAX action registered in the framework/admin/control-panel…
- CVE-2022-1659HIGHCVSS 5.4EG 7.32022-06-13
Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which can be used to call any function in the includes/condition/class-condition-manager.php file by sending the desired functi…
- CVE-2022-1753MEDIUMCVSS 5.4EG 5.42022-05-17
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. …
- CVE-2022-1958HIGHCVSS 6.3EG 8.82022-06-15
A vulnerability classified as critical has been found in FileCloud. Affected is an unknown function of the component NTFS Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. Upgrading …
- CVE-2022-1959MEDIUMCVSS 6.6EG 6.62022-09-30
AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is possible because the application did not correctly implement fingerprint validations.
- CVE-2022-20358LOWCVSS 3.3EG 3.32022-08-10
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges ne…
- CVE-2022-2052CRITICALCVSS 9.8EG 9.82022-10-17
Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.
- CVE-2022-20696HIGHCVSS 7.5EG 8.82022-09-08
A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected…
- CVE-2022-20716HIGHCVSS 7.8EG 7.82022-04-15
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain escalated privileges. This vulnerability is due to improper access control on files within the affected system. A local attacker could…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →