← Back
CWE-284

7,463 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,463)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Repository Visibility Manipulation via Git Push Options
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Local File Inclusion via file:// URI in Migration Restore
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
REST API exposes organization membership of private organizations to public
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Gitea SSH Key Parser Denial of Service
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Privilege Escalation via Access Token Scope Escalation in API
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Email Management API Bypasses ManageCredentials Feature Restrictions
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service
-
-
Sep 9, 2026
Aug 13, 2026
7.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extensi...Show more
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10.Show less
-
-
Aug 28, 2026
Aug 13, 2026
N/A· v4
8.6 HIGH· v3
N/A· v2
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All vers...Show more
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.Show less
-
-
Aug 28, 2026
Aug 13, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All vers...Show more
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.Show less
-
-
Aug 26, 2026
Aug 13, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is pu...Show more
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.Show less
1Ibm
1Informix Dynamic Server
Aug 18, 2026
Aug 12, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
1Dell
1Display And Peripheral Manager
Aug 17, 2026
Aug 12, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, lea...Show more
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.Show less
1Dell
1Display And Peripheral Manager
Aug 17, 2026
Aug 12, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulne...Show more
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.Show less
-
-
Aug 26, 2026
Aug 12, 2026
6.3 MEDIUM· v4
N/A· v3
N/A· v2
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in q...Show more
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.Show less
-
-
Aug 26, 2026
Aug 12, 2026
5.3 MEDIUM· v4
N/A· v3
N/A· v2
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissi...Show more
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on files owned by other users.Show less
-
-
Aug 26, 2026
Aug 12, 2026
6.9 MEDIUM· v4
N/A· v3
N/A· v2
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permis...Show more
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, delete, overwrite, re-assign permissions) on every file managed within the extension.Show less