CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,304 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 58 of 127
- CVE-2024-32483HIGHCVSS 8.2EG 8.22024-11-13
Improper access control for some Intel(R) EMA software before version 1.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-3270LOWCVSS 3.8EG 3.82024-04-03
A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to improper access controls. The attack can be initiated remot…
- CVE-2024-3279CRITICALCVSS 9.1EG 9.12024-08-12
An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in the application, to import their…
- CVE-2024-32939MEDIUMCVSS 4.3EG 4.32024-08-22
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configure…
- CVE-2024-32940MEDIUMCVSS 6.5EG 6.52024-09-16
Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via adjacent access.
- CVE-2024-32969LOWCVSS 2.7EG 2.72024-05-23
vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra organizations to their collaboration that can extend their influence. For example, organizations that they include can th…
- CVE-2024-32973MEDIUMCVSS 4.8EG 4.82024-05-01
Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. In affected versions an attacker with the ability to actively intercept network traffic would be able to use a specifically-crafted certificate to fool Pluto into …
- CVE-2024-33027HIGHCVSS 8.4EG 8.42024-08-05
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
- CVE-2024-33227HIGHCVSS 8.8EG 8.82024-05-22
An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
- CVE-2024-33260MEDIUMCVSS 5.1EG 5.12024-04-26
Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at jerry-core/parser/js/js-parser-expr.c
- CVE-2024-33393MEDIUMCVSS 6.2EG 6.22024-05-01
An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
- CVE-2024-33396HIGHCVSS 8.4EG 8.42024-05-02
An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
- CVE-2024-33647MEDIUMCVSS 6.5EG 6.52024-05-14
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in the affected application lacks proper access controls. This could allow an authenticated user to query items beyond the u…
- CVE-2024-33666HIGHCVSS 8.6EG 8.62024-04-26
An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via the API. This data should be available only to agents.
- CVE-2024-33673HIGHCVSS 7.8EG 7.82024-04-26
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path.
- CVE-2024-33898CRITICALCVSS 9.8EG 9.82024-06-24
Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution.
- CVE-2024-34022MEDIUMCVSS 6.7EG 6.72024-11-13
Improper Access Control in some Thunderbolt(TM) Share software before version 1.0.49.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-3404MEDIUMCVSS 6.5EG 6.52024-06-06
In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read …
- CVE-2024-34068MEDIUMCVSS 6.4EG 6.42024-05-03
Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal e…
- CVE-2024-34099HIGHCVSS 7.8EG 7.82024-05-15
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires u…
- CVE-2024-34107MEDIUMCVSS 5.3EG 5.32024-06-13
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass securi…
- CVE-2024-34112HIGHCVSS 7.5EG 7.52024-06-13
ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could exploit this vulnerability to gain unauthorized access to sensitive…
- CVE-2024-34152MEDIUMCVSS 4.3EG 4.32024-05-26
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRun…
- CVE-2024-34221HIGHCVSS 8.8EG 8.82024-05-14
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.
- CVE-2024-34404MEDIUMCVSS 6.8EG 6.82024-05-03
A vulnerability was discovered in the Alta Recovery Vault feature of Veritas NetBackup before 10.4 and NetBackup Appliance before 5.4. By design, only the cloud administrator should be able to disable the retention lock of Governance mode …
- CVE-2024-34543MEDIUMCVSS 6.7EG 6.72024-09-16
Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-34725HIGHCVSS 7.0EG 7.42024-07-09
In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User intera…
- CVE-2024-3504HIGHCVSS 6.5EG 8.12024-06-06
An improper access control vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, where an admin can update any organization user to the organization owner. This vulnerability allows the elevated user to delete projec…
- CVE-2024-35122LOWCVSS 2.8EG 2.82025-01-24
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint with the privileges of a user socially e…
- CVE-2024-35177HIGHCVSS 7.8EG 7.82025-02-03
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. The wazuh-agent for Windows i…
- CVE-2024-35222MEDIUMCVSS 5.9EG 5.92024-05-23
Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications can access the Tauri IPC endpoints without being explicitly allowed in the `dangerousRemoteDomainIpcAccess` in v1 and i…
- CVE-2024-35396CRITICALCVSS 9.8EG 9.82024-05-24
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.
- CVE-2024-35433HIGHCVSS 8.1EG 8.12024-05-30
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.
- CVE-2024-36068CRITICALCVSS 9.8EG 9.82024-08-27
An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to execute arbitrary code.
- CVE-2024-36080CRITICALCVSS 9.8EG 9.82024-05-19
Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.
- CVE-2024-36241LOWCVSS 3.1EG 3.12024-05-26
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command
- CVE-2024-36247MEDIUMCVSS 4.6EG 4.62024-09-16
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacent access.
- CVE-2024-36257LOWCVSS 2.7EG 2.72024-07-03
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that ac…
- CVE-2024-36259HIGHCVSS 7.5EG 7.52025-02-25
Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.
- CVE-2024-36261LOWCVSS 3.5EG 3.52024-09-16
Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.
- CVE-2024-36293MEDIUMCVSS 6.5EG 6.52025-02-12
Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2024-36323HIGHCVSS 8.8EG 8.82026-05-15
Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perform unauthorized access to the register space of the JPEG cores assigned a victim VM/process, potentially gaining arbit…
- CVE-2024-36399HIGHCVSS 8.2EG 8.22024-06-06
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL pa…
- CVE-2024-36438HIGHCVSS 7.3EG 7.32024-07-15
eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other attacks.
- CVE-2024-36441MEDIUMCVSS 5.4EG 5.42024-08-22
Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device.
- CVE-2024-36443HIGHCVSS 7.6EG 7.62024-08-22
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.
- CVE-2024-36488HIGHCVSS 7.3EG 7.32024-11-13
Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-36492HIGHCVSS 7.4EG 7.42024-08-01
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of local users when syncing users in shared channels. which allows a malicious remote to overwrite an existing local user.
- CVE-2024-36505MEDIUMCVSS 5.1EG 5.12024-08-13
An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via …
- CVE-2024-36535CRITICALCVSS 9.8EG 9.82024-07-24
Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →