CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,302 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 64 of 127
- CVE-2024-52911HIGHCVSS 7.5EG 7.52026-05-05
Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14.
- CVE-2024-52928CRITICALCVSS 9.6EG 9.62025-06-26
Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.
- CVE-2024-53010HIGHCVSS 7.8EG 7.82025-06-03
Memory corruption may occur while attaching VM when the HLOS retains access to VM.
- CVE-2024-53304MEDIUMCVSS 6.5EG 6.52025-04-16
An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands via posing as an infected machine.
- CVE-2024-5331MEDIUMCVSS 4.3EG 4.32024-08-01
The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1.7.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to export form submi…
- CVE-2024-53348HIGHCVSS 7.4EG 7.42025-03-21
LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privileges.
- CVE-2024-53351CRITICALCVSS 9.8EG 9.82025-03-21
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.
- CVE-2024-53494HIGHCVSS 7.5EG 7.52025-08-22
Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication.
- CVE-2024-53495HIGHCVSS 7.5EG 7.52025-08-20
Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.
- CVE-2024-53496CRITICALCVSS 9.8EG 9.82025-08-22
Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.
- CVE-2024-53542MEDIUMCVSS 6.5EG 6.52025-02-24
Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.
- CVE-2024-53573CRITICALCVSS 9.8EG 9.82025-02-26
Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}.
- CVE-2024-54038MEDIUMCVSS 4.3EG 4.32024-12-10
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measure…
- CVE-2024-54096MEDIUMCVSS 5.3EG 5.32024-12-12
Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy.
- CVE-2024-5430MEDIUMCVSS 6.8EG 6.82024-06-27
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request…
- CVE-2024-54533HIGHCVSS 7.0EG 7.02025-03-31
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access sensitive user data.
- CVE-2024-54556LOWCVSS 2.4EG 2.42026-01-16
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may be able to view restricted content from the lock screen.
- CVE-2024-54559MEDIUMCVSS 5.5EG 5.52025-03-17
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.
- CVE-2024-54565MEDIUMCVSS 6.2EG 6.22025-03-17
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.
- CVE-2024-5470LOWCVSS 3.8EG 3.82024-07-11
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.
- CVE-2024-55019HIGHCVSS 7.5EG 7.52026-03-03
Incorrect access control in the component download_wb.cgi of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows unauthenticated attack to download arbitrary files.
- CVE-2024-55025MEDIUMCVSS 6.5EG 6.52026-03-03
Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to access the HMI system.
- CVE-2024-55402MEDIUMCVSS 5.3EG 5.32025-08-06
4C Strategies Exonaut before v22.4 was discovered to contain an access control issue.
- CVE-2024-55954HIGHCVSS 8.7EG 8.72025-01-16
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Root" user from the organization. This violates the intended pr…
- CVE-2024-55963MEDIUMCVSS 6.5EG 6.52025-03-26
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limit…
- CVE-2024-56195MEDIUMCVSS 6.3EG 6.32025-03-06
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 9.2.9 or 10.0.4, which fixes the …
- CVE-2024-56196MEDIUMCVSS 6.3EG 6.32025-03-06
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.
- CVE-2024-56330CRITICALCVSS 9.3EG 9.32024-12-20
Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC) is not disabled. This would allow users within a container to access another containers agent, therefore compromising …
- CVE-2024-56335HIGHCVSS 7.6EG 7.62024-12-20
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attack…
- CVE-2024-5650HIGHCVSS 8.5EG 8.52024-06-17
DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by repl…
- CVE-2024-5655CRITICALCVSS 9.6EG 9.62024-06-27
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user …
- CVE-2024-5687MEDIUMCVSS 5.3EG 5.32024-06-11
If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. The triggering principal is used to calculate many values, including the `Referer` and `Se…
- CVE-2024-56883HIGHCVSS 8.1EG 8.12025-02-18
Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external cours…
- CVE-2024-56889HIGHCVSS 7.5EG 7.52025-02-06
Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.
- CVE-2024-56898HIGHCVSS 8.8EG 8.82025-02-03
Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, m…
- CVE-2024-57032CRITICALCVSS 9.8EG 9.82025-01-17
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.
- CVE-2024-5714HIGHCVSS 6.8EG 7.42024-06-27
In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissions to manipulate project identifiers in requests, enabling them to invite users to projects in other organizations, ch…
- CVE-2024-57152HIGHCVSS 7.5EG 7.52025-08-20
Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class
- CVE-2024-57154CRITICALCVSS 9.8EG 9.82025-08-20
Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.
- CVE-2024-57155CRITICALCVSS 9.8EG 9.82025-08-20
Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token.
- CVE-2024-57157CRITICALCVSS 9.8EG 9.82025-08-20
Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.
- CVE-2024-57190CRITICALCVSS 9.8EG 9.82025-06-10
Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.
- CVE-2024-57249CRITICALCVSS 6.5EG 9.42025-02-07
Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a vulnerability in access control mechanisms by removing authentication-related HTTP headers…
- CVE-2024-57336MEDIUMCVSS 6.5EG 6.52025-05-28
Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Administrator account access.
- CVE-2024-57360HIGHCVSS 5.5EG 7.72025-01-21
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.
- CVE-2024-57378HIGHCVSS 7.3EG 7.32025-02-13
Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthori…
- CVE-2024-57433HIGHCVSS 7.5EG 7.52025-01-31
macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state.
- CVE-2024-5814MEDIUMCVSS 5.3EG 5.32024-08-27
A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully pars…
- CVE-2024-58330HIGHCVSS 7.5EG 7.52026-07-23
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.
- CVE-2024-5840MEDIUMCVSS 6.5EG 6.52024-06-11
Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →