CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,289 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 37 of 126
- CVE-2022-4689HIGHCVSS 8.8EG 8.82022-12-23
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
- CVE-2022-46890MEDIUMCVSS 4.3EG 4.32023-01-19
Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is caused by a lack of checks performed by the /forums.php?action=post page).
- CVE-2022-46892CRITICALCVSS 9.8EG 9.82023-02-15
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.
- CVE-2022-4700HIGHCVSS 5.4EG 8.82023-01-10
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those wit…
- CVE-2022-4702MEDIUMCVSS 5.4EG 6.52023-01-10
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those wit…
- CVE-2022-4703HIGHCVSS 4.3EG 8.12023-01-10
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with …
- CVE-2022-47036CRITICALCVSS 9.8EG 9.82024-03-18
Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the…
- CVE-2022-47037HIGHCVSS 7.5EG 7.52024-03-18
Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.
- CVE-2022-4704HIGHCVSS 5.4EG 8.12023-01-10
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with s…
- CVE-2022-4705MEDIUMCVSS 4.3EG 4.32023-01-10
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with s…
- CVE-2022-4708MEDIUMCVSS 4.3EG 6.52023-01-10
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those wi…
- CVE-2022-4709MEDIUMCVSS 4.3EG 6.52023-01-10
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those wit…
- CVE-2022-4711MEDIUMCVSS 4.3EG 4.32023-01-10
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_mega_menu_settings' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those wit…
- CVE-2022-4724CRITICALCVSS 9.8EG 9.82022-12-27
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- CVE-2022-47407MEDIUMCVSS 6.5EG 6.52022-12-14
An issue was discovered in the fp_masterquiz (aka Master-Quiz) extension before 2.2.1, and 3.x before 3.5.1, for TYPO3. An attacker can continue the quiz of a different user. In doing so, the attacker can view that user's answers and modif…
- CVE-2022-47542HIGHCVSS 8.8EG 8.82023-03-30
Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.
- CVE-2022-47543MEDIUMCVSS 5.3EG 5.32023-01-05
An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects.
- CVE-2022-47558CRITICALCVSS 9.4EG 9.42023-09-19
Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or …
- CVE-2022-47634HIGHCVSS 8.1EG 8.12023-01-01
M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LINK-2867.
- CVE-2022-47648HIGHCVSS 7.6EG 8.82023-02-08
An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring any sort of authorization or authentication due to the IP based authorization. If an authorized user has accessed a publi…
- CVE-2022-47699CRITICALCVSS 9.8EG 9.82023-01-31
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control.
- CVE-2022-4807MEDIUMCVSS 4.3EG 4.32022-12-28
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4809HIGHCVSS 8.8EG 8.82022-12-28
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4810MEDIUMCVSS 4.3EG 4.32022-12-28
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4814MEDIUMCVSS 4.3EG 4.32022-12-28
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-48615MEDIUMCVSS 4.8EG 4.82023-12-12
An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information.
- CVE-2022-48683HIGHCVSS 7.8EG 7.82024-06-10
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13. An app may be able to break out of its sandbox.
- CVE-2023-0012MEDIUMCVSS 6.4EG 6.72023-01-10
In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default al…
- CVE-2023-0017CRITICALCVSS 9.4EG 9.82023-01-10
An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unaut…
- CVE-2023-0120LOWCVSS 3.5EG 3.52023-09-01
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was poss…
- CVE-2023-0319MEDIUMCVSS 5.8EG 5.82023-04-05
An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to …
- CVE-2023-0348HIGHCVSS 7.5EG 7.52023-03-13
Akuvox E11 allows direct SIP calls. No access control is enforced by the SIP servers, which could allow an attacker to contact any device within Akuvox to call any other device.
- CVE-2023-0451HIGHCVSS 7.5EG 7.52023-01-26
Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration files. One such file contains tables with MD5 hashes and usernames for all defined use…
- CVE-2023-0506HIGHCVSS 8.8EG 8.82023-10-03
The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain …
- CVE-2023-0551MEDIUMCVSS 5.4EG 5.42023-08-16
The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
- CVE-2023-0661MEDIUMCVSS 6.5EG 6.52023-02-12
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
- CVE-2023-0744CRITICALCVSS 9.8EG 9.82023-02-08
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
- CVE-2023-0811CRITICALCVSS 9.1EG 9.12023-03-16
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM password is stored. If an adversary issues a PROGRAM AREA WRITE command to a specific memory region, they could overwrite the password. This may…
- CVE-2023-0858LOWCVSS 3.1EG 3.12023-05-11
Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Ser…
- CVE-2023-0916HIGHCVSS 6.3EG 8.82023-02-19
A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads to improper access…
- CVE-2023-0963CRITICALCVSS 7.3EG 9.82023-02-22
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper a…
- CVE-2023-0998MEDIUMCVSS 6.5EG 6.52023-02-24
A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipulation of the argum…
- CVE-2023-1007HIGHCVSS 5.3EG 7.82023-02-24
A vulnerability was found in Twister Antivirus 8.17. It has been declared as critical. This vulnerability affects the function 0x801120E4 in the library filmfd.sys of the component IoControlCode Handler. The manipulation leads to improper …
- CVE-2023-1208HIGHCVSS 7.2EG 7.22023-07-10
This HTTP Headers WordPress plugin before 1.18.11 allows arbitrary data to be written to arbitrary files, leading to a Remote Code Execution vulnerability.
- CVE-2023-1432CRITICALCVSS 7.3EG 9.82023-03-16
A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /fos/admin/ajax.php?action=save_settings of the component POST Request…
- CVE-2023-1453HIGHCVSS 4.4EG 7.12023-03-17
A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to i…
- CVE-2023-1486HIGHCVSS 4.4EG 7.12023-03-18
A vulnerability classified as problematic was found in Lespeed WiseCleaner Wise Force Deleter 1.5.3.54. This vulnerability affects the function 0x220004 in the library WiseUnlock64.sys of the component IoControlCode Handler. The manipulati…
- CVE-2023-1489HIGHCVSS 7.8EG 7.82023-03-18
A vulnerability has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54 and classified as critical. Affected by this vulnerability is the function 0x9C402088 in the library WiseHDInfo64.dll of the component IoControlCode Handler…
- CVE-2023-1490MEDIUMCVSS 4.4EG 5.52023-03-18
A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1 and classified as critical. Affected by this issue is the function 0x220020 in the library SDActMon.sys of the component IoControlCode Handler. The manipulation leads to impr…
- CVE-2023-1491MEDIUMCVSS 4.4EG 5.52023-03-18
A vulnerability was found in Max Secure Anti Virus Plus 19.0.2.1. It has been classified as critical. This affects the function 0x220020 in the library MaxCryptMon.sys of the component IoControlCode Handler. The manipulation leads to impro…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →