CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 19 of 126
- CVE-2018-19634HIGHCVSS 7.5EG 7.52019-01-22
CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.
- CVE-2018-19945CRITICALCVSS 9.1EG 9.12020-12-31
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitations of a pathname to a restricted directory, this vulnerability allows for renaming arbitrary files on the target syste…
- CVE-2018-20890MEDIUMCVSS 4.3EG 4.32019-08-01
cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).
- CVE-2018-20930MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
- CVE-2018-20938LOWCVSS 2.7EG 2.72019-08-01
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).
- CVE-2018-20957HIGHCVSS 8.8EG 8.82019-08-08
The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks.
- CVE-2018-21007CRITICALCVSS 9.8EG 9.82019-08-29
The woo-confirmation-email plugin before 3.2.0 for WordPress has no blocking of direct access to supportive xl folders inside uploads.
- CVE-2018-25092MEDIUMCVSS 5.5EG 5.52023-11-05
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper …
- CVE-2018-25093MEDIUMCVSS 5.5EG 5.52023-11-06
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgr…
- CVE-2018-3762MEDIUMCVSS 4.3EG 4.32018-07-05
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
- CVE-2018-4844MEDIUMCVSS 6.7EG 6.72018-03-20
A vulnerability has been identified in SIMATIC WinCC OA UI for Android (All versions < V3.15.10), SIMATIC WinCC OA UI for iOS (All versions < V3.15.10). Insufficient limitation of CONTROL script capabilities could allow read and write acce…
- CVE-2018-4845HIGHCVSS 8.8EG 8.82018-06-26
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Sieme…
- CVE-2018-4858HIGHCVSS 7.8EG 7.82018-07-09
A vulnerability has been identified in IEC 61850 system configurator (All versions < V5.80), DIGSI 5 (affected as IEC 61850 system configurator is incorporated) (All versions < V7.80), DIGSI 4 (All versions < V4.93), SICAM PAS/PQS (All ver…
- CVE-2018-5264MEDIUMCVSS 5.9EG 5.92019-06-07
Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cookie in a /guest/s/def…
- CVE-2018-5406HIGHCVSS 8.8EG 8.82019-06-03
The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated, remote attacker could exploit this vulnerability to perfor…
- CVE-2018-7362HIGHCVSS 7.5EG 8.82018-11-16
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which may allows an unauthorized user to perform unauthorized operations on the router.
- CVE-2018-7364CRITICALCVSS 9.8EG 9.82018-12-07
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vuln…
- CVE-2018-7520CRITICALCVSS 9.8EG 9.82018-03-22
An improper access control vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which could allow a full configuration download, including passwords.
- CVE-2018-7791CRITICALCVSS 9.8EG 9.82018-08-29
A Permissions, Privileges, and Access Control vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firmware V1.6.2.0). The vulnerability allows unauthorized users to overwrite the origina…
- CVE-2018-7847CRITICALCVSS 9.8EG 9.82019-05-22
A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration se…
- CVE-2018-8922MEDIUMCVSS 6.5EG 6.52018-06-01
Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders via unspecified vectors.
- CVE-2019-0036CRITICALCVSS 9.8EG 9.82019-04-10
When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silently ignored. No warning is issued during configuration, and the config is committed withou…
- CVE-2019-0041HIGHCVSS 8.6EG 8.62019-04-10
On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The device may fail to forward such traffic. This issue affects Juniper Networks Junos OS 18.2 vers…
- CVE-2019-1010316HIGHCVSS 7.8EG 7.82019-07-11
pyxtrlock 0.3 and earlier is affected by: Incorrect Access Control. The impact is: False locking impression when run in a non-X11 session. The fixed version is: 0.4.
- CVE-2019-10127HIGHCVSS 8.8EG 8.82021-03-19
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inheri…
- CVE-2019-10128HIGHCVSS 7.8EG 7.82021-03-19
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the …
- CVE-2019-10130MEDIUMCVSS 4.3EG 4.32019-07-30
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, suc…
- CVE-2019-10138HIGHCVSS 8.8EG 8.82019-07-30
A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA token…
- CVE-2019-10161HIGHCVSS 7.8EG 7.82019-07-30
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd proces…
- CVE-2019-10166HIGHCVSS 7.8EG 7.82019-08-02
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed sa…
- CVE-2019-10167HIGHCVSS 7.8EG 7.82019-08-02
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that pro…
- CVE-2019-10168HIGHCVSS 7.8EG 7.82019-08-02
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libv…
- CVE-2019-10175MEDIUMCVSS 6.5EG 6.52019-06-28
A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine whether the requesting user has permission to access the Persistent Volume Claim (PVC) in the s…
- CVE-2019-10187MEDIUMCVSS 4.3EG 4.32019-07-31
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.
- CVE-2019-10188MEDIUMCVSS 4.3EG 4.32019-07-31
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
- CVE-2019-10189MEDIUMCVSS 4.3EG 4.32019-07-31
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.
- CVE-2019-10200HIGHCVSS 7.2EG 7.22021-03-19
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nod…
- CVE-2019-10925HIGHCVSS 7.1EG 7.12019-06-12
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). An authenticated attacker could escalate privileges by sending specially crafted requests to the integrated webserver. The security vulnerability can be e…
- CVE-2019-10938CRITICALCVSS 9.8EG 9.82019-08-02
A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 and CP100 (All versions < V8.01), Siemens Power Meters Series 9410 (All versions < V2.2.1)…
- CVE-2019-10950CRITICALCVSS 9.8EG 9.82019-04-30
Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits t…
- CVE-2019-10962MEDIUMCVSS 5.3EG 5.32019-06-13
BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Work…
- CVE-2019-10964HIGHCVSS 7.1EG 7.12019-06-28
Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not pro…
- CVE-2019-10970CRITICALCVSS 9.8EG 9.82019-07-11
In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelView 5510 Graphic Disp…
- CVE-2019-11634CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-22
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
- CVE-2019-11780HIGHCVSS 8.1EG 8.12019-12-19
Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to priv…
- CVE-2019-11782MEDIUMCVSS 6.5EG 6.52020-12-22
Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users with access to contact management to modify user accounts, leading to privilege escalation.
- CVE-2019-11783MEDIUMCVSS 6.5EG 6.52020-12-22
Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to subscribe to arbitrary mail channels uninvited.
- CVE-2019-11784MEDIUMCVSS 6.5EG 6.52020-12-22
Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authenticated users to obtain access to arbitrary messages in conversations they were not a party…
- CVE-2019-11785MEDIUMCVSS 4.3EG 4.32020-12-22
Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to obtain access to messages posted on business records there were not given acce…
- CVE-2019-11786MEDIUMCVSS 4.3EG 4.32020-12-22
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authenticated users to modify translated terms, which may lead to arbitrary content modification on translatable elements.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →