CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,295 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 55 of 126
- CVE-2024-22830MEDIUMCVSS 5.3EG 5.32024-05-01
Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control when handling system resources. This allows a local attacker to escalate privileges from regular user to System or PPL le…
- CVE-2024-2315HIGHCVSS 7.1EG 7.12024-11-12
APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected SPI flash modifications and BIOS boot kit launches, also impacting th…
- CVE-2024-23238HIGHCVSS 3.3EG 7.12024-03-08
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to edit NVRAM variables.
- CVE-2024-23266MEDIUMCVSS 5.5EG 5.52024-03-08
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system.
- CVE-2024-23267MEDIUMCVSS 5.5EG 5.52024-03-08
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to bypass certain Privacy preferences.
- CVE-2024-23271HIGHCVSS 6.5EG 7.32024-04-24
A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.
- CVE-2024-23315HIGHCVSS 7.5EG 7.52024-05-28
A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to a disclosure of sensitive information. An…
- CVE-2024-23331HIGHCVSS 7.5EG 7.52024-01-19
Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers hosted on Windows. T…
- CVE-2024-23351HIGHCVSS 8.4EG 8.42024-05-06
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
- CVE-2024-23360HIGHCVSS 8.4EG 8.42024-06-03
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
- CVE-2024-23446MEDIUMCVSS 6.5EG 6.52024-02-07
An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DLS) or Field-level security (FLS) when querying the .alerts-security.alerts-{space_id} indices. Users who are authorized…
- CVE-2024-23447MEDIUMCVSS 5.3EG 5.32024-02-07
An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions to a file, with explicit allow write and deny read. Although the document is not accessible to the user in Network Driv…
- CVE-2024-23488LOWCVSS 3.1EG 3.12024-02-29
Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disa…
- CVE-2024-23663HIGHCVSS 8.8EG 8.82024-07-09
An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request.
- CVE-2024-23675MEDIUMCVSS 6.5EG 6.52024-01-22
In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of K…
- CVE-2024-23681HIGHCVSS 8.2EG 8.22024-01-19
Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker can abuse this issue to execute arbitrary Java when a victi…
- CVE-2024-23920HIGHCVSS 8.8EG 8.82025-01-31
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists wi…
- CVE-2024-24300CRITICALCVSS 9.8EG 9.82024-02-14
4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.
- CVE-2024-24386HIGHCVSS 7.2EG 7.22024-02-15
An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.
- CVE-2024-2447MEDIUMCVSS 6.5EG 6.52024-04-05
Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via…
- CVE-2024-24485HIGHCVSS 7.5EG 7.52024-04-15
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command.
- CVE-2024-24486CRITICALCVSS 9.1EG 9.12024-04-15
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.
- CVE-2024-24487MEDIUMCVSS 6.8EG 6.82024-04-15
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the EXEC REBOOT SYSTEM command.
- CVE-2024-24496CRITICALCVSS 9.8EG 9.82024-02-08
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.
- CVE-2024-24566MEDIUMCVSS 5.3EG 5.32024-01-31
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is password-protected (deployed with the `ACCESS_CODE` option), it is possible to access plugins …
- CVE-2024-24568MEDIUMCVSS 5.3EG 5.32024-02-26
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patch…
- CVE-2024-24693HIGHCVSS 7.2EG 7.22024-03-13
Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.
- CVE-2024-24751MEDIUMCVSS 4.3EG 4.32024-02-13
sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extens…
- CVE-2024-24771HIGHCVSS 7.7EG 7.72024-02-07
Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their credentials (username + password) compromise…
- CVE-2024-24776LOWCVSS 3.1EG 3.12024-02-09
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.
- CVE-2024-2481MEDIUMCVSS 6.5EG 6.52024-03-15
A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the file /admin/manage-students.php. The manipulation of the argument del leads to improper ac…
- CVE-2024-24824HIGHCVSS 8.8EG 8.82024-02-07
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. …
- CVE-2024-24830CRITICALCVSS 9.9EG 9.92024-02-08
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any a…
- CVE-2024-24902MEDIUMCVSS 6.6EG 6.62024-12-13
Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exploit this vulnerability leading to gaining access to unauthorized data for a limited time.
- CVE-2024-24986HIGHCVSS 8.8EG 8.82024-08-14
Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-25106CRITICALCVSS 9.1EG 9.12024-02-08
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulner…
- CVE-2024-25120MEDIUMCVSS 4.3EG 4.32024-02-13
TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pa…
- CVE-2024-25121HIGHCVSS 7.1EG 7.12024-02-13
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to…
- CVE-2024-25133HIGHCVSS 8.8EG 8.82024-12-31
A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands o…
- CVE-2024-25169CRITICALCVSS 9.8EG 9.82024-02-28
An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.
- CVE-2024-25251HIGHCVSS 8.8EG 8.82024-02-22
code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.
- CVE-2024-25501HIGHCVSS 8.8EG 8.82024-03-09
An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.
- CVE-2024-25576HIGHCVSS 7.9EG 7.92024-08-14
improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access.
- CVE-2024-25653MEDIUMCVSS 4.3EG 4.32024-03-14
Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system reports and modify custom reports via the Report functionality in the Web U…
- CVE-2024-25677HIGHCVSS 8.8EG 8.82024-02-09
In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.
- CVE-2024-25723HIGHCVSS 8.8EG 8.92024-02-27
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with…
- CVE-2024-25735CRITICALCVSS 9.1EG 9.12024-03-27
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.
- CVE-2024-25736HIGHCVSS 7.5EG 7.52024-03-27
An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.
- CVE-2024-25811MEDIUMCVSS 6.5EG 6.52024-03-21
An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
- CVE-2024-25830CRITICALCVSS 9.8EG 9.82024-02-29
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A su…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →