CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,295 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 54 of 126
- CVE-2024-21112HIGHCVSS 8.8EG 8.82024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infr…
- CVE-2024-21113HIGHCVSS 8.8EG 8.82024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infr…
- CVE-2024-21114HIGHCVSS 8.8EG 8.82024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infr…
- CVE-2024-21115HIGHCVSS 8.8EG 8.82024-04-16
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infr…
- CVE-2024-21132MEDIUMCVSS 5.4EG 5.42024-07-16
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Approvals). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access…
- CVE-2024-21145MEDIUMCVSS 4.8EG 4.82024-07-16
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3…
- CVE-2024-21150MEDIUMCVSS 6.1EG 6.12024-07-16
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker wit…
- CVE-2024-21153HIGHCVSS 8.1EG 8.12024-07-16
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows lo…
- CVE-2024-21169MEDIUMCVSS 6.5EG 6.52024-07-16
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Partners). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access …
- CVE-2024-21195HIGHCVSS 7.6EG 7.62024-10-15
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged atta…
- CVE-2024-21247LOWCVSS 3.8EG 3.82024-10-15
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privil…
- CVE-2024-21248MEDIUMCVSS 5.3EG 5.32024-10-15
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Difficult to exploit vulnerability allows low privileged attacker …
- CVE-2024-21302MEDIUMCVSS 6.7EG 6.72024-08-08
Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE f…
- CVE-2024-21364CRITICALCVSS 9.3EG 9.32024-02-13
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
- CVE-2024-21376CRITICALCVSS 9.0EG 9.02024-02-13
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
- CVE-2024-21401CRITICALCVSS 9.8EG 9.82024-02-13
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
- CVE-2024-21418HIGHCVSS 7.8EG 7.82024-03-12
Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability
- CVE-2024-21424MEDIUMCVSS 6.5EG 6.52024-04-09
Azure Compute Gallery Elevation of Privilege Vulnerability
- CVE-2024-21436HIGHCVSS 7.8EG 7.82024-03-12
Windows Installer Elevation of Privilege Vulnerability
- CVE-2024-21483MEDIUMCVSS 4.6EG 4.62024-03-12
A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3120 DC (7KM3120-1BA0…
- CVE-2024-21589HIGHCVSS 7.4EG 7.42024-01-12
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated network-based attacker to access reports without authenticating, potentially containing sensitive configura…
- CVE-2024-21644HIGHCVSS 7.5EG 7.82024-01-08
pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0…
- CVE-2024-21653MEDIUMCVSS 6.5EG 6.52024-01-30
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh config by default that permits root login with password authen…
- CVE-2024-21665MEDIUMCVSS 4.3EG 4.32024-01-11
ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access the back-office orders list and be able to query over the information returned. Access control and permissions are not …
- CVE-2024-21666MEDIUMCVSS 6.5EG 6.52024-01-11
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation. An authenticated and unauthorized user can access the list of potential duplicate …
- CVE-2024-21667MEDIUMCVSS 6.5EG 6.52024-01-11
pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An authenticated and unauthorized user can access the GDPR data extraction feature and query over the information returned…
- CVE-2024-21740HIGHCVSS 7.4EG 7.42024-06-25
Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.
- CVE-2024-21741CRITICALCVSS 9.8EG 9.82024-06-25
GigaDevice GD32E103C8T6 devices have Incorrect Access Control.
- CVE-2024-21767CRITICALCVSS 9.4EG 9.42024-03-01
A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.
- CVE-2024-21805HIGHCVSS 7.8EG 7.82024-03-12
Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who …
- CVE-2024-21828MEDIUMCVSS 6.7EG 6.72024-05-16
Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-21848LOWCVSS 3.1EG 3.12024-04-05
Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel
- CVE-2024-2191MEDIUMCVSS 5.3EG 5.32024-06-27
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite…
- CVE-2024-22026MEDIUMCVSS 6.7EG 6.72024-05-22
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.
- CVE-2024-22067MEDIUMCVSS 6.8EG 6.82024-11-18
ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
- CVE-2024-22074CRITICALCVSS 9.8EG 9.82024-06-06
Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control. This is fixed in 1.8.2014, …
- CVE-2024-2217HIGHCVSS 7.5EG 7.52024-04-10
gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling atta…
- CVE-2024-22187CRITICALCVSS 9.1EG 9.12024-05-28
A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can…
- CVE-2024-22202MEDIUMCVSS 5.7EG 5.72024-02-05
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user removal page allows an attacker to spoof another user's detail, and in turn make a compelling phishing case for removing…
- CVE-2024-22206CRITICALCVSS 9.0EG 9.02024-01-12
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.
- CVE-2024-22209MEDIUMCVSS 6.4EG 6.42024-01-13
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.
- CVE-2024-22216CRITICALCVSS 10.0EG 10.02024-01-08
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information di…
- CVE-2024-22234HIGHCVSS 7.4EG 7.42024-02-20
In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method. …
- CVE-2024-22316MEDIUMCVSS 4.3EG 4.32025-01-27
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perform unauthorized actions to another user's data due to improper access controls.
- CVE-2024-22407MEDIUMCVSS 4.9EG 4.92024-01-16
Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate i…
- CVE-2024-22415HIGHCVSS 7.3EG 7.32024-01-18
jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without configured file s…
- CVE-2024-22459MEDIUMCVSS 6.8EG 6.82024-02-28
Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to…
- CVE-2024-22807MEDIUMCVSS 6.5EG 6.52024-04-22
An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the flash memory, causing the machine to lose network connectivity and suffer from firmware corruption.
- CVE-2024-2281MEDIUMCVSS 6.3EG 6.32024-03-08
A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the component Setting Handler. The manipulation leads to …
- CVE-2024-22811HIGHCVSS 8.2EG 8.22024-04-22
An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the Hostmot2 configu…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →