← Back
CWE-284

5,090 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Nov 21, 2024
Mar 13, 2024
N/A· v4
5.8 MEDIUM· v3
N/A· v2
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnera...Show more
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to improper assignment of lookup keys to internal interface contexts. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to access resources behind the affected device that were supposed to be protected by a configured ACL.Show less
1Theme Fusion
1Avada
Apr 8, 2026
Mar 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for aut...Show more
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attackers, with contributor access and above, to view the contents of all form submissions, including fields that are obfuscated (such as the contact form's "password" field).Show less
1Themegrill
1Maintenance Page
Apr 8, 2026
Mar 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles...Show more
The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles and content when the site is in maintenance mode.Show less
1Themegrill
1Maintenance Page
Apr 8, 2026
Mar 13, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0...Show more
The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber access or higher, to download a csv containing subscriber emails.Show less
1Dev.institute
1Restrict User Access
Apr 8, 2026
Mar 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via API. This makes it possible for unauthenticated...Show more
The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages via API.Show less
1Duitku
1Duitku Payment Gateway
Apr 8, 2026
Mar 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_duitku_response function in all versions up to, and including, 2.11.6. Thi...Show more
The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_duitku_response function in all versions up to, and including, 2.11.6. This makes it possible for unauthenticated attackers to change the payment status of orders to failed.Show less
1Lifterlms
1Lifterlms
Apr 8, 2026
Mar 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_review' function in all versions up to, and inc...Show more
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_review' function in all versions up to, and including, 7.5.1. This makes it possible for unauthenticated attackers to publish an unrestricted number of reviews on the site.Show less
1Pawaryogesh1989
1Bulk Edit Post Titles
Apr 8, 2026
Mar 13, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkUpdatePostTitles function in all versions up to, and including, 5.0.0. This m...Show more
The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkUpdatePostTitles function in all versions up to, and including, 5.0.0. This makes it possible for authenticated attackers, with subscriber access and above, to modify the titles of arbitrary posts.Show less
1W3eden
1Download Manager
Apr 8, 2026
Mar 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to do...Show more
The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published).Show less
1Totolink
1A8000ru Firmware
Apr 3, 2025
Mar 12, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.
1Microsoft
1Azure Data Studio
Jan 15, 2025
Mar 12, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Azure Data Studio Elevation of Privilege Vulnerability
1Microsoft
1Intune Company Portal
Dec 6, 2024
Mar 12, 2024
N/A· v4
6.6 MEDIUM· v3
N/A· v2
Microsoft Intune Linux Agent Elevation of Privilege Vulnerability
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Dec 27, 2024
Mar 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Installer Elevation of Privilege Vulnerability
1Linuxfoundation
1Software For Open Networking In The Cloud
Dec 27, 2024
Mar 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability
1Fortinet
1Fortimanager
Nov 21, 2024
Mar 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or...Show more
A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.Show less
-
-
Nov 21, 2024
Mar 12, 2024
5.1 MEDIUM· v4
4.6 MEDIUM· v3
N/A· v2
A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC31...Show more
A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3120 DC (7KM3120-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 AC/DC (7KM3220-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)), SENTRON 7KM PAC3220 DC (7KM3220-1BA01-1EA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( with LQNYYMMDD...)). The read out protection of the internal flash of affected devices was not properly set at the end of the manufacturing process. An attacker with physical access to the device could read out the data.Show less
1Siemens
1Sinema Remote Connect Server
Nov 21, 2024
Mar 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to...Show more
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to code execution.Show less
1Skygroup
1Skysea Client View
May 23, 2025
Mar 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific fo...Show more
Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's Windows client is installed. In case the file is a specially crafted DLL file, arbitrary code may be executed with SYSTEM privilege.Show less
1Codeium
1Codeium
Feb 26, 2025
Mar 11, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check the sender when receiving an external message. This allows an attacker...Show more
codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check the sender when receiving an external message. This allows an attacker to host a website that will steal the user's Codeium api-key, and thus impersonate the user on the backend autocomplete server. This issue has not been addressed. Users are advised to monitor the usage of their API key.Show less
1Winmail
1Winmail
Sep 18, 2025
Mar 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue WinMail v.7.1 and v.5.1 and before allows a remote attacker to execute arbitrary code via a crafted script to the email parameter.