CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,294 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 49 of 126
- CVE-2023-52801CRITICALCVSS 9.1EG 9.12024-05-21
In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_area_split(), if the original iopt_area has filled a domain and is linked to domains_itree…
- CVE-2023-5288CRITICALCVSS 9.8EG 9.82023-09-29
A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.
- CVE-2023-52972MEDIUMCVSS 5.5EG 5.52025-03-26
Huawei PCs have a vulnerability that allows low-privilege users to bypass SDDL permission checks . Successful exploitation this vulnerability could lead to termination of some system processes.
- CVE-2023-5299HIGHCVSS 8.8EG 8.82023-11-22
A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system.
- CVE-2023-5352MEDIUMCVSS 4.3EG 4.32023-11-06
The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.
- CVE-2023-5353HIGHCVSS 6.5EG 8.12023-10-03
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
- CVE-2023-5354MEDIUMCVSS 6.1EG 6.12023-11-06
The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
- CVE-2023-5355HIGHCVSS 8.1EG 8.12023-11-06
The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.
- CVE-2023-5365CRITICALCVSS 9.8EG 9.82023-10-09
HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.
- CVE-2023-5454HIGHCVSS 7.5EG 7.52023-11-06
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.
- CVE-2023-5542MEDIUMCVSS 4.3EG 4.32023-11-09
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
- CVE-2023-5543LOWCVSS 3.3EG 3.32023-11-09
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.
- CVE-2023-5549MEDIUMCVSS 5.3EG 5.32023-11-09
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
- CVE-2023-5833HIGHCVSS 8.8EG 8.82023-10-30
Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.
- CVE-2023-5916MEDIUMCVSS 4.3EG 4.32023-11-02
A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /config-manager/save of the component Configuration Handler. The manipulation of the argument config leads to improper a…
- CVE-2023-5976MEDIUMCVSS 4.3EG 4.32023-11-07
Improper Access Control in GitHub repository microweber/microweber prior to 2.0.
- CVE-2023-5995HIGHCVSS 7.5EG 7.52023-12-01
An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the p…
- CVE-2023-6073MEDIUMCVSS 6.3EG 6.32023-11-10
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio volume to maximum …
- CVE-2023-6202MEDIUMCVSS 4.3EG 4.32023-11-27
Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Matter…
- CVE-2023-6259HIGHCVSS 7.1EG 7.62024-02-19
Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue affects ACS100, ACS300: from 5.2.4 before 6.2.4.3.
- CVE-2023-6491MEDIUMCVSS 4.3EG 4.32024-06-07
The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possibl…
- CVE-2023-6547MEDIUMCVSS 5.4EG 5.42023-12-12
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if …
- CVE-2023-6578HIGHCVSS 6.5EG 7.32023-12-07
A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. It is possible to launch t…
- CVE-2023-6582MEDIUMCVSS 5.3EG 5.32024-01-11
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attacker…
- CVE-2023-6733MEDIUMCVSS 6.5EG 6.52024-01-04
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.8 via the wpmem_field shortcode. This makes it possible for authenticated attackers, with contr…
- CVE-2023-6758MEDIUMCVSS 4.3EG 5.32023-12-13
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads to improper access …
- CVE-2023-6761HIGHCVSS 8.8EG 8.82023-12-13
A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper access controls. The atta…
- CVE-2023-6773HIGHCVSS 8.8EG 8.82023-12-13
A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /accounts_con/register_account of the component User …
- CVE-2023-6785MEDIUMCVSS 5.3EG 5.32024-03-13
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added …
- CVE-2023-6810MEDIUMCVSS 4.3EG 4.32024-05-07
The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function in all versions up to, and including, 3.2.4. This makes it possible fo…
- CVE-2023-6840MEDIUMCVSS 6.7EG 6.72024-02-07
An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy…
- CVE-2023-6930CRITICALCVSS 9.8EG 9.82023-12-19
EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to disclose sensitive information and assist in authentication bypass, privilege esc…
- CVE-2023-6955MEDIUMCVSS 6.6EG 6.62024-01-12
A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group tha…
- CVE-2023-6966HIGHCVSS 8.1EG 8.12024-06-06
The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX functions in the /core/core_ajax.php file in all versions up to…
- CVE-2023-6968HIGHCVSS 8.1EG 8.12024-06-06
The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.6.3. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for un…
- CVE-2023-7025HIGHCVSS 7.8EG 7.82023-12-21
A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the function init_kcm of the component DBus Handler. The manipulation leads to improper access con…
- CVE-2023-7028CRITICALCVSS 10.0EG 10.0⚠ KEV2024-01-12
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which …
- CVE-2023-7055MEDIUMCVSS 5.4EG 5.42023-12-22
A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /user/profile.php of the component Contact Information Handler. The manipulation of the arg…
- CVE-2023-7193HIGHCVSS 8.1EG 8.12023-12-31
A vulnerability was found in MTab Bookmark up to 1.2.6 and classified as critical. This issue affects some unknown processing of the file public/install.php of the component Installation. The manipulation leads to improper access controls.…
- CVE-2023-7223MEDIUMCVSS 6.5EG 6.52024-01-09
A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input showSyslog leads to imp…
- CVE-2024-0025HIGHCVSS 7.8EG 7.82024-05-07
In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is n…
- CVE-2024-0032MEDIUMCVSS 6.5EG 6.82024-02-16
In multiple locations, there is a possible way to request access to directories that should be hidden due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interactio…
- CVE-2024-0036HIGHCVSS 7.8EG 7.82024-02-16
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to bypass the restrictions on starting activities from the background due to a logic error in the code. This could lead to local escalation of privile…
- CVE-2024-0104MEDIUMCVSS 4.2EG 4.22024-08-08
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tam…
- CVE-2024-0199HIGHCVSS 7.7EG 7.72024-03-07
An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old featur…
- CVE-2024-0212HIGHCVSS 8.1EG 8.12024-01-29
The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from the Cloudflare API.
- CVE-2024-0258HIGHCVSS 8.6EG 8.62024-03-08
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may be able to execute arbitrary code out of its sandbox or with certain elevated pr…
- CVE-2024-0324HIGHCVSS 8.2EG 8.22024-02-05
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authenticati…
- CVE-2024-0336CRITICALCVSS 9.4EG 9.42024-06-03
Missing Authentication for Critical Function vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDKS: from V3.04 before 20240603. NOTE: The vendor was contacted ear…
- CVE-2024-0356MEDIUMCVSS 4.3EG 4.32024-01-10
A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file updateRoles of the component Backend. The manipulation leads to improper acc…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →