CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,297 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 59 of 126
- CVE-2024-36537HIGHCVSS 7.2EG 7.22024-07-24
Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2024-36540CRITICALCVSS 9.8EG 9.82024-07-24
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2024-36989HIGHCVSS 7.1EG 7.12024-07-01
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin …
- CVE-2024-37147MEDIUMCVSS 4.3EG 4.32024-07-10
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write acces…
- CVE-2024-37155MEDIUMCVSS 6.5EG 6.52024-11-18
OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Prior to version 6.1.9, the regex validation used to prevent Introspection queries can be bypassed by removing t…
- CVE-2024-37279MEDIUMCVSS 4.3EG 4.32024-06-13
A flaw was discovered in Kibana, allowing view-only users of alerting to use the run_soon API making the alerting rule run continuously, potentially affecting the system availability if the alerting rule is running complex queries.
- CVE-2024-37289HIGHCVSS 7.8EG 7.82024-06-10
An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the…
- CVE-2024-37312MEDIUMCVSS 6.3EG 6.32024-06-14
user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recomm…
- CVE-2024-37314LOWCVSS 3.5EG 3.52024-06-14
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 o…
- CVE-2024-37315LOWCVSS 3.5EG 3.52024-06-14
Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upg…
- CVE-2024-37317MEDIUMCVSS 4.6EG 4.62024-06-14
The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal …
- CVE-2024-37341HIGHCVSS 8.8EG 8.82024-09-10
Microsoft SQL Server Elevation of Privilege Vulnerability
- CVE-2024-37355HIGHCVSS 8.8EG 8.82025-02-12
Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-37386MEDIUMCVSS 4.2EG 4.22024-07-15
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fi…
- CVE-2024-3746MEDIUMCVSS 5.5EG 5.52024-04-30
The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or overwrite files.
- CVE-2024-37566CRITICALCVSS 9.8EG 9.82025-02-27
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
- CVE-2024-37567CRITICALCVSS 9.1EG 9.12025-02-27
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.
- CVE-2024-37568HIGHCVSS 7.5EG 7.52024-06-09
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CV…
- CVE-2024-3765CRITICALCVSS 9.8EG 9.82024-04-14
A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, AHB7004T-MHV2, AHB8032F-LME and XM530_R80X30-PQ_8M. Affected by this vulnerability is an unknown functionality of the co…
- CVE-2024-37677HIGHCVSS 7.5EG 7.52024-06-24
An issue in Shenzhen Weitillage Industrial Co., Ltd the access management specialist V6.62.51215 allows a remote attacker to obtain sensitive information.
- CVE-2024-37742HIGHCVSS 8.2EG 8.22024-06-25
Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk mode and the underlying system, compromising exam integrity. By exploiting this flaw,…
- CVE-2024-3777CRITICALCVSS 9.8EG 9.82024-04-15
The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.
- CVE-2024-37882HIGHCVSS 8.1EG 8.12024-06-14
Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.…
- CVE-2024-37883MEDIUMCVSS 4.3EG 4.32024-06-14
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted c…
- CVE-2024-37884LOWCVSS 3.5EG 3.52024-06-14
Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.…
- CVE-2024-37887LOWCVSS 3.5EG 3.52024-06-14
Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Next…
- CVE-2024-37905HIGHCVSS 8.8EG 8.82024-06-28
authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining…
- CVE-2024-37993MEDIUMCVSS 5.3EG 5.32024-09-10
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC Reader RF610R FCC (6GT2811-6BC10-1AA0) (All versi…
- CVE-2024-38016HIGHCVSS 7.8EG 7.82024-09-19
Microsoft Office Visio Remote Code Execution Vulnerability
- CVE-2024-38061HIGHCVSS 7.5EG 7.52024-07-09
DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability
- CVE-2024-38100HIGHCVSS 7.8EG 7.82024-07-09
Windows File Explorer Elevation of Privilege Vulnerability
- CVE-2024-38162HIGHCVSS 7.8EG 7.82024-08-13
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- CVE-2024-38163HIGHCVSS 7.8EG 7.82024-08-14
Windows Update Stack Elevation of Privilege Vulnerability
- CVE-2024-38164CRITICALCVSS 9.6EG 9.62024-07-23
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.
- CVE-2024-38175CRITICALCVSS 9.6EG 9.62024-08-20
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
- CVE-2024-38195HIGHCVSS 7.8EG 7.82024-08-13
Azure CycleCloud Remote Code Execution Vulnerability
- CVE-2024-38202HIGHCVSS 7.3EG 7.32024-08-08
Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some featur…
- CVE-2024-38204HIGHCVSS 7.5EG 7.52024-10-15
Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
- CVE-2024-38220CRITICALCVSS 9.0EG 9.02024-09-10
Azure Stack Hub Elevation of Privilege Vulnerability
- CVE-2024-38223MEDIUMCVSS 6.8EG 6.82024-08-13
Windows Initial Machine Configuration Elevation of Privilege Vulnerability
- CVE-2024-38273MEDIUMCVSS 5.4EG 5.42024-06-18
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
- CVE-2024-38291HIGHCVSS 8.8EG 8.82025-02-27
In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.
- CVE-2024-38310HIGHCVSS 8.2EG 8.22025-02-12
Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-38371HIGHCVSS 8.6EG 8.62024-06-28
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens…
- CVE-2024-38518MEDIUMCVSS 4.6EG 4.62024-06-28
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. On…
- CVE-2024-38873MEDIUMCVSS 5.3EG 5.32024-06-21
An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote use…
- CVE-2024-38909CRITICALCVSS 9.8EG 9.82024-07-30
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
- CVE-2024-39274HIGHCVSS 8.7EG 8.72024-08-01
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malici…
- CVE-2024-39285MEDIUMCVSS 5.3EG 5.32024-11-13
Improper access control in UEFI firmware in some Intel(R) Server M20NTP Family may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2024-39327CRITICALCVSS 9.9EG 9.92025-02-18
Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →