CWE-284
7,463 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,463)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Repository Visibility Manipulation via Git Push Options |
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints |
Local File Inclusion via file:// URI in Migration Restore |
REST API exposes organization membership of private organizations to public |
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload |
Gitea Remember-Me Token Theft Not Invalidating Attacker Session |
Gitea SSH Key Parser Denial of Service |
Privilege Escalation via Access Token Scope Escalation in API |
Email Management API Bypasses ManageCredentials Feature Restrictions |
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service |
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extensi...Show more |
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All vers...Show more |
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All vers...Show more |
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is pu...Show more |
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. |
1Dell 1Display And Peripheral Manager Aug 17, 2026 Aug 12, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, lea...Show more |
1Dell 1Display And Peripheral Manager Aug 17, 2026 Aug 12, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulne...Show more |
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in q...Show more |
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissi...Show more |
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permis...Show more |