CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,277 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 28 of 126
- CVE-2021-36913HIGHCVSS 7.5EG 7.52022-10-11
Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= 2.4.0 at WordPress allows attackers to change options and inject scripts into the footer HTML. Requires an additional e…
- CVE-2021-36917HIGHCVSS 6.5EG 7.52021-11-24
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
- CVE-2021-37183MEDIUMCVSS 6.5EG 6.52021-09-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software allows sending send-to-sleep notifications to the managed devices. An unauthenticated attacker in the same network of the …
- CVE-2021-37864MEDIUMCVSS 2.6EG 6.52022-01-18
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly acc…
- CVE-2021-38392HIGHCVSS 6.5EG 7.62021-10-04
A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable device in any region in …
- CVE-2021-38417HIGHCVSS 7.4EG 7.52022-07-27
VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.
- CVE-2021-38454CRITICALCVSS 10.0EG 10.02021-10-12
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
- CVE-2021-38457CRITICALCVSS 9.8EG 9.82021-10-22
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication.
- CVE-2021-3864HIGHCVSS 7.0EG 7.02022-08-26
A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The de…
- CVE-2021-39333HIGHCVSS 8.1EG 8.12021-11-01
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all …
- CVE-2021-3967HIGHCVSS 8.8EG 8.82022-02-26
Improper Access Control in GitHub repository zulip/zulip prior to 4.10.
- CVE-2021-3987MEDIUMCVSS 4.3EG 4.32024-11-15
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not v…
- CVE-2021-3992MEDIUMCVSS 6.5EG 6.52021-12-01
kimai2 is vulnerable to Improper Access Control
- CVE-2021-40112CRITICALCVSS 10.0EG 10.02021-11-04
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following acti…
- CVE-2021-40113CRITICALCVSS 10.0EG 10.02021-11-04
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following acti…
- CVE-2021-40130MEDIUMCVSS 4.9EG 4.92021-11-19
A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restric…
- CVE-2021-4016MEDIUMCVSS 4.0EG 4.02022-01-21
Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset…
- CVE-2021-4026MEDIUMCVSS 4.3EG 4.32021-11-30
bookstack is vulnerable to Improper Access Control
- CVE-2021-4037HIGHCVSS 7.8EG 7.82022-08-24
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permissi…
- CVE-2021-40404CRITICALCVSS 6.5EG 9.82022-01-28
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to tri…
- CVE-2021-40405MEDIUMCVSS 6.5EG 6.52022-04-14
A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vu…
- CVE-2021-40413HIGHCVSS 7.1EG 8.82022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of…
- CVE-2021-40414HIGHCVSS 7.1EG 8.82022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The SetMdAlarm API sets the movement detection parameters, giving the ability to set the sen…
- CVE-2021-40415MEDIUMCVSS 6.5EG 6.52022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In cgi_check_ability the Format API does not have a specific case, the user permission will …
- CVE-2021-40416HIGHCVSS 8.8EG 8.82022-01-28
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any lo…
- CVE-2021-40699HIGHCVSS 7.4EG 7.42023-09-07
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerabi…
- CVE-2021-4089MEDIUMCVSS 4.3EG 4.32021-12-10
snipe-it is vulnerable to Improper Access Control
- CVE-2021-4119CRITICALCVSS 9.8EG 9.82021-12-15
bookstack is vulnerable to Improper Access Control
- CVE-2021-41194CRITICALCVSS 9.1EG 9.12021-10-28
FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthori…
- CVE-2021-41298HIGHCVSS 8.8EG 8.82021-09-30
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with general user's privile…
- CVE-2021-41543MEDIUMCVSS 6.5EG 6.52022-03-08
A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information…
- CVE-2021-41834MEDIUMCVSS 5.3EG 6.52022-05-23
JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality can be used by a low-privileged user to read and copy any artifact that exists in the Artifactory deployment due to impro…
- CVE-2021-4194MEDIUMCVSS 6.5EG 6.52022-01-06
bookstack is vulnerable to Improper Access Control
- CVE-2021-4201CRITICALCVSS 9.6EG 9.62022-02-14
Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access …
- CVE-2021-42029HIGHCVSS 7.8EG 7.82022-04-12
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (All versions < V16 Update 5), SIMATIC STEP 7 (TIA Portal) V17 (All versions < V17 Update 2). An attacker could achieve …
- CVE-2021-42116MEDIUMCVSS 4.3EG 4.32021-11-30
Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for highe…
- CVE-2021-42124HIGHCVSS 8.8EG 8.82021-12-07
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
- CVE-2021-42359CRITICALCVSS 7.5EG 9.12021-11-05
WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting unsubscription…
- CVE-2021-42360HIGHCVSS 7.6EG 7.62021-11-17
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-proc…
- CVE-2021-42808MEDIUMCVSS 6.5EG 6.52021-12-20
Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges.
- CVE-2021-42855HIGHCVSS 7.8EG 7.82022-03-10
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is subsequently used by…
- CVE-2021-4300CRITICALCVSS 6.3EG 9.82023-01-04
A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the function CBlock::AddToBlockIndex of the file src/main.cpp of the component Block Verification. The manipulation leads t…
- CVE-2021-43019HIGHCVSS 7.8EG 7.82021-11-23
Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and esca…
- CVE-2021-4338MEDIUMCVSS 6.4EG 6.42023-06-07
The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated att…
- CVE-2021-4352MEDIUMCVSS 5.3EG 5.32023-06-07
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_locsettings function in versions up to, and including, 1.8.1. This makes it possible for unauthenticated at…
- CVE-2021-4360CRITICALCVSS 9.9EG 9.92023-06-07
The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a n…
- CVE-2021-4361HIGHCVSS 8.8EG 8.82023-06-07
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_job_integrations_settin_save AJAX action in versions up to, and including, 1.8.1. This makes it possib…
- CVE-2021-4364MEDIUMCVSS 4.3EG 4.32023-06-07
The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the jobsearch_add_job_import_schedule_call() function in versions up to, and including, 1.8.1. This makes it possibl…
- CVE-2021-4380CRITICALCVSS 9.8EG 9.82023-06-07
The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, …
- CVE-2021-43986HIGHCVSS 6.0EG 7.82022-04-20
The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve privilege escalation.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →