CWE-284— Improper Access Control
4,239 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 49 of 85
- CVE-2024-45334HIGHCVSS 7.8EG 7.82024-10-22
Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that could allow unauthorized access to product configurations and functions.
- CVE-2024-45371MEDIUMCVSS 6.7EG 6.72025-05-13
Improper access control for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6077 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-45392HIGHCVSS 7.7EG 7.72024-09-05
SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete records via the API. Versions 7.14.5 and 8.6.2 contain a patch f…
- CVE-2024-45397MEDIUMCVSS 5.9EG 5.92024-10-11
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the IP-address-based access control is used, the access control…
- CVE-2024-45408HIGHCVSS 7.5EG 7.52024-10-01
eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated user to access several kinds of otherwise restricted information. If anonymous access is al…
- CVE-2024-45432HIGHCVSS 7.5EG 7.52025-09-12
OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable used as a function argument. An attacker can leverage this…
- CVE-2024-45438CRITICALCVSS 9.1EG 9.12025-08-21
An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions usin…
- CVE-2024-45489CRITICALCVSS 9.8EG 9.82024-09-20
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another use…
- CVE-2024-45509MEDIUMCVSS 6.5EG 9.82024-09-01
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.
- CVE-2024-45519CRITICALCVSS 10.0EG 10.0⚠ KEV2024-10-02
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
- CVE-2024-45522CRITICALCVSS 9.8EG 9.12024-09-02
Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.
- CVE-2024-45734MEDIUMCVSS 4.3EG 4.32024-10-14
In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk clas…
- CVE-2024-45735MEDIUMCVSS 4.3EG 4.32024-10-14
In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged user that does not hold the "admin" or "power" Splunk roles can se…
- CVE-2024-45811MEDIUMCVSS 4.8EG 4.82024-09-17
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL b…
- CVE-2024-45870MEDIUMCVSS 6.5EG 6.52024-10-03
Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.
- CVE-2024-45982HIGHCVSS 8.8EG 8.82024-09-26
A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and c…
- CVE-2024-46097HIGHCVSS 8.1EG 8.12024-09-27
TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id para…
- CVE-2024-46280HIGHCVSS 8.8EG 8.82024-09-30
PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a root-level account, without the possibility of changing them.
- CVE-2024-46412MEDIUMCVSS 6.5EG 6.52025-08-25
Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a crafted GET request sent to /commons/ip-location.
- CVE-2024-46430MEDIUMCVSS 6.5EG 8.02025-02-10
Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the administrator password by sending a specially crafted…
- CVE-2024-46432HIGHCVSS 8.8EG 8.02025-02-10
Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized changes to WiFi configuration settings and…
- CVE-2024-46539HIGHCVSS 8.2EG 8.22024-10-08
Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).
- CVE-2024-46607HIGHCVSS 7.6EG 7.62024-09-25
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
- CVE-2024-46609HIGHCVSS 7.5EG 7.32024-09-25
An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
- CVE-2024-46610HIGHCVSS 7.5EG 7.52024-09-25
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function i…
- CVE-2024-46627CRITICALCVSS 9.1EG 9.12024-09-26
Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
- CVE-2024-46916HIGHCVSS 8.1EG 8.12025-08-29
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remo…
- CVE-2024-46937HIGHCVSS 7.5EG 9.12024-09-16
An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain access to user token…
- CVE-2024-46948MEDIUMCVSS 4.3EG 4.32024-11-08
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
- CVE-2024-46990MEDIUMCVSS 5.0EG 5.02024-09-18
Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like …
- CVE-2024-47145LOWCVSS 3.1EG 3.12024-09-26
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.
- CVE-2024-47481MEDIUMCVSS 6.5EG 6.52024-10-25
Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Denial of service.
- CVE-2024-47758HIGHCVSS 8.8EG 8.82024-12-11
GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 1…
- CVE-2024-47760HIGHCVSS 8.8EG 8.82024-12-11
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch…
- CVE-2024-47910HIGHCVSS 7.2EG 7.22024-10-04
An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing configuration of a GitHub integration to exfiltrate a pre-signed JWT.
- CVE-2024-47975HIGHCVSS 7.0EG 7.02024-10-07
Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker with local access to potentially enable denial of service.
- CVE-2024-47976MEDIUMCVSS 6.7EG 6.72024-10-07
Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.
- CVE-2024-48010MEDIUMCVSS 6.5EG 6.52024-11-08
Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to escalation of privile…
- CVE-2024-48899MEDIUMCVSS 4.3EG 4.32024-11-20
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course badges for courses that they are intended to have access to.
- CVE-2024-48905CRITICALCVSS 9.1EG 9.12025-05-01
Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
- CVE-2024-48912HIGHCVSS 8.1EG 8.12024-12-11
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an application endpoint to delete any user account. Version 10.0.17 contains a patch for this i…
- CVE-2024-48925NONECVSS 0.0EG 0.02024-10-22
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve inform…
- CVE-2024-48932MEDIUMCVSS 5.3EG 5.32024-10-24
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, the API endpoint `http://<Server-ip>/v1/users/name` allows unauthenticated users to access sensitive information, such …
- CVE-2024-48955HIGHCVSS 8.1EG 8.12024-10-29
Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not encrypted and as the system does not validate the session authorization…
- CVE-2024-49044MEDIUMCVSS 6.7EG 6.72024-11-12
Visual Studio Elevation of Privilege Vulnerability
- CVE-2024-49049HIGHCVSS 7.1EG 7.12024-11-12
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
- CVE-2024-49068HIGHCVSS 8.2EG 8.22024-12-12
Microsoft SharePoint Elevation of Privilege Vulnerability
- CVE-2024-49105HIGHCVSS 8.4EG 8.42024-12-12
Remote Desktop Client Remote Code Execution Vulnerability
- CVE-2024-49107HIGHCVSS 7.3EG 7.32024-12-12
WmsRepair Service Elevation of Privilege Vulnerability
- CVE-2024-49600HIGHCVSS 7.8EG 7.82024-12-09
Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privil…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →