CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,295 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 56 of 126
- CVE-2024-25852HIGHCVSS 8.8EG 8.82024-04-11
Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.
- CVE-2024-25962HIGHCVSS 8.3EG 8.32024-03-27
Dell InsightIQ, version 5.0, contains an improper access control vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to monitoring data.
- CVE-2024-25980MEDIUMCVSS 4.3EG 4.32024-02-19
Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.
- CVE-2024-25981MEDIUMCVSS 4.3EG 4.32024-02-19
Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.
- CVE-2024-26022HIGHCVSS 7.8EG 7.82024-08-14
Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-26029HIGHCVSS 7.5EG 7.52024-06-13
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gai…
- CVE-2024-26119MEDIUMCVSS 5.3EG 5.32024-03-18
Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to achieve a low-confidentiality impac…
- CVE-2024-26139HIGHCVSS 8.3EG 8.32024-05-23
OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack of certain security controls on the profile edit functionality, an authenticated attacker with low p…
- CVE-2024-26201MEDIUMCVSS 6.6EG 6.62024-03-12
Microsoft Intune Linux Agent Elevation of Privilege Vulnerability
- CVE-2024-26203HIGHCVSS 7.3EG 7.32024-03-12
Azure Data Studio Elevation of Privilege Vulnerability
- CVE-2024-26234MEDIUMCVSS 6.7EG 6.72024-04-09
Proxy Driver Spoofing Vulnerability
- CVE-2024-26263MEDIUMCVSS 5.3EG 5.32024-02-15
EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login.
- CVE-2024-26310MEDIUMCVSS 4.3EG 4.32024-02-21
Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access to API information that should only be accessible with ext…
- CVE-2024-2698HIGHCVSS 8.8EG 8.82024-06-12
A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag on S4U2Self tickets. Fixing this mistake required adding a special case for the ch…
- CVE-2024-27187HIGHCVSS 7.5EG 7.52024-08-20
Improper Access Controls allows backend users to overwrite their username when disallowed.
- CVE-2024-27200MEDIUMCVSS 4.4EG 4.42024-11-13
Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-27264HIGHCVSS 7.4EG 7.42024-05-22
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-For…
- CVE-2024-2731MEDIUMCVSS 5.4EG 5.42024-04-10
Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages that expose sensitive information such as company names, users' names and surnames, stage names, and monitoring campaig…
- CVE-2024-27348CRITICALCVSS 9.8EG 9.8⚠ KEV2024-04-22
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth sy…
- CVE-2024-2749MEDIUMCVSS 5.9EG 5.92024-05-14
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthoriz…
- CVE-2024-27497HIGHCVSS 8.8EG 8.82024-03-01
Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
- CVE-2024-27602CRITICALCVSS 9.1EG 9.12024-04-02
Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.
- CVE-2024-27605HIGHCVSS 7.5EG 7.52024-04-02
Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system.
- CVE-2024-27790HIGHCVSS 7.5EG 7.52024-05-14
Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replyi…
- CVE-2024-27792MEDIUMCVSS 5.5EG 5.52024-06-10
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.
- CVE-2024-27803LOWCVSS 2.4EG 2.42024-05-14
A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to share items from the lock screen.
- CVE-2024-27819LOWCVSS 2.4EG 2.42024-06-10
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to access contacts from the lock screen.
- CVE-2024-27841CRITICALCVSS 5.5EG 9.82024-05-14
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.
- CVE-2024-27855HIGHCVSS 8.8EG 8.82024-06-10
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. A shortcut may be able to use sensitive data with certain actions without…
- CVE-2024-27891MEDIUMCVSS 5.3EG 5.32026-06-04
On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or…
- CVE-2024-27895HIGHCVSS 7.5EG 7.52024-04-08
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2024-28016MEDIUMCVSS 6.0EG 6.02024-03-28
Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, …
- CVE-2024-28050MEDIUMCVSS 5.0EG 5.02024-08-14
Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-28087MEDIUMCVSS 6.5EG 6.52024-05-15
In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable.
- CVE-2024-28115HIGHCVSS 8.8EG 8.82024-03-07
FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming techniques should a vulnerability exist t…
- CVE-2024-28120MEDIUMCVSS 6.5EG 6.52024-03-11
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check the sender when receiving an external message. This allows an attacker to host a website t…
- CVE-2024-28170LOWCVSS 3.3EG 3.32024-09-16
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2024-28215HIGHCVSS 7.5EG 7.52024-03-07
nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.
- CVE-2024-28216MEDIUMCVSS 5.4EG 5.42024-03-07
nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.
- CVE-2024-28338HIGHCVSS 8.0EG 8.02024-03-12
A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.
- CVE-2024-28390CRITICALCVSS 9.8EG 9.82024-03-14
An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access Control.
- CVE-2024-28405HIGHCVSS 7.2EG 7.22024-03-29
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.
- CVE-2024-2880LOWCVSS 2.7EG 2.72024-07-11
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with `admin_group_member` custom role permission…
- CVE-2024-28805CRITICALCVSS 9.1EG 9.12024-07-29
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.
- CVE-2024-28818MEDIUMCVSS 5.9EG 5.92024-06-05
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, Exynos Modem 5300. The…
- CVE-2024-28917MEDIUMCVSS 6.2EG 6.22024-04-09
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
- CVE-2024-28922MEDIUMCVSS 4.1EG 4.12024-04-09
Secure Boot Security Feature Bypass Vulnerability
- CVE-2024-28960HIGHCVSS 8.2EG 8.22024-03-29
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
- CVE-2024-28965MEDIUMCVSS 5.4EG 5.42024-06-13
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this…
- CVE-2024-28966MEDIUMCVSS 5.4EG 5.42024-06-13
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →