CWE-284— Improper Access Control
4,211 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 14 of 85
- CVE-2021-33162HIGHCVSS 8.4EG 8.42024-02-23
Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-34401HIGHCVSS 7.8EG 7.82022-01-18
NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to code execution, compromised integrity, or denial of service.
- CVE-2021-34402MEDIUMCVSS 6.7EG 6.72022-01-18
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial o…
- CVE-2021-34626MEDIUMCVSS 4.3EG 4.32021-07-07
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
- CVE-2021-34627MEDIUMCVSS 4.3EG 4.32021-07-07
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
- CVE-2021-34696MEDIUMCVSS 5.8EG 5.82021-09-23
A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrec…
- CVE-2021-34724MEDIUMCVSS 6.0EG 6.02021-09-23
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on…
- CVE-2021-34753MEDIUMCVSS 5.8EG 5.82024-11-15
A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. Thi…
- CVE-2021-34754MEDIUMCVSS 5.8EG 7.52021-10-27
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffi…
- CVE-2021-34794MEDIUMCVSS 5.3EG 5.32021-10-27
A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated,…
- CVE-2021-34795CRITICALCVSS 10.0EG 9.82021-11-04
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following acti…
- CVE-2021-34864HIGHCVSS 8.8EG 8.82021-10-25
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to…
- CVE-2021-35213HIGHCVSS 8.9EG 8.82021-08-31
An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a guest user to elevate privileges to the Administrator using this vulnerability. Authentication…
- CVE-2021-35221MEDIUMCVSS 6.3EG 8.12021-08-31
Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.
- CVE-2021-35245HIGHCVSS 8.4EG 6.82021-12-06
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
- CVE-2021-35249MEDIUMCVSS 4.3EG 4.32022-05-17
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only …
- CVE-2021-35528HIGHCVSS 7.2EG 7.12021-11-17
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. …
- CVE-2021-3554CRITICALCVSS 9.0EG 10.02021-11-24
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects…
- CVE-2021-36036HIGHCVSS 7.2EG 7.22023-09-06
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the websit…
- CVE-2021-3626HIGHCVSS 8.8EG 8.82021-10-01
The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.
- CVE-2021-36775HIGHCVSS 8.8EG 8.82022-04-04
a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions pr…
- CVE-2021-36776HIGHCVSS 8.8EG 8.82022-04-04
A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.
- CVE-2021-36888CRITICALCVSS 9.8EG 9.82021-12-15
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
- CVE-2021-36909HIGHCVSS 8.8EG 8.12021-11-18
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and ta…
- CVE-2021-36913HIGHCVSS 7.5EG 7.52022-10-11
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional e…
- CVE-2021-36917MEDIUMCVSS 6.5EG 7.52021-11-24
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
- CVE-2021-37183MEDIUMCVSS 6.5EG 6.52021-09-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software allows sending send-to-sleep notifications to the managed devices. An unauthenticated attacker in the same network of the …
- CVE-2021-37864LOWCVSS 2.6EG 6.52022-01-18
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly acc…
- CVE-2021-38392MEDIUMCVSS 6.5EG 7.62021-10-04
A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable device in any region in …
- CVE-2021-38417HIGHCVSS 7.4EG 7.52022-07-27
VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.
- CVE-2021-38454CRITICALCVSS 10.0EG 10.02021-10-12
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
- CVE-2021-38457CRITICALCVSS 9.8EG 9.82021-10-22
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication.
- CVE-2021-3864HIGHCVSS 7.0EG 7.02022-08-26
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The de…
- CVE-2021-39333HIGHCVSS 8.1EG 8.12021-11-01
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all …
- CVE-2021-3967HIGHCVSS 8.8EG 8.82022-02-26
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
- CVE-2021-3987MEDIUMCVSS 4.3EG 4.32024-11-15
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not v…
- CVE-2021-3992MEDIUMCVSS 6.5EG 6.52021-12-01
kimai2 is vulnerable to Improper Access Control
- CVE-2021-40112CRITICALCVSS 10.0EG 7.52021-11-04
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following acti…
- CVE-2021-40113CRITICALCVSS 10.0EG 9.82021-11-04
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following acti…
- CVE-2021-40130MEDIUMCVSS 4.9EG 4.92021-11-19
A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restric…
- CVE-2021-4016MEDIUMCVSS 4.0EG 3.32022-01-21
Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset…
- CVE-2021-4026MEDIUMCVSS 4.3EG 4.32021-11-30
bookstack is vulnerable to Improper Access Control
- CVE-2021-4037HIGHCVSS 7.8EG 7.82022-08-24
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permissi…
- CVE-2021-40404MEDIUMCVSS 6.5EG 9.82022-01-28
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to tri…
- CVE-2021-40405MEDIUMCVSS 6.5EG 6.52022-04-14
A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vu…
- CVE-2021-40413HIGHCVSS 7.1EG 8.82022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of…
- CVE-2021-40414HIGHCVSS 7.1EG 8.82022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The SetMdAlarm API sets the movement detection parameters, giving the ability to set the sen…
- CVE-2021-40415MEDIUMCVSS 6.5EG 6.52022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In cgi_check_ability the Format API does not have a specific case, the user permission will …
- CVE-2021-40416HIGHCVSS 8.8EG 8.82022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any lo…
- CVE-2021-40699HIGHCVSS 7.4EG 7.42023-09-07
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerabi…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →