← Back
CWE-284

5,090 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Eurotel
1Etl3100 Firmware
Nov 21, 2024
Dec 19, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to disclose sensitive information and assist in authentication by...Show more
EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to disclose sensitive information and assist in authentication bypass, privilege escalation, and full system access. Show less
1Ethex
1Ethex Contracts
Nov 21, 2024
Dec 19, 2023
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in Ethex Contracts. It has been classified as critical. This affects an unknown part of the file EthexJackpot.sol of the component Monthly Jackpot Handler. The manipulation leads to improper acc...Show more
A vulnerability was found in Ethex Contracts. It has been classified as critical. This affects an unknown part of the file EthexJackpot.sol of the component Monthly Jackpot Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is named 6b8664b698d3d953e16c284fadc6caeb9e58e3db. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248271.Show less
2Debian
Openbsd
2Debian Linux
Openssh
May 28, 2026
Dec 18, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only appli...Show more
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.Show less
1Bosch
6Cpp13 Firmware
Cpp14 FirmwareCpp4 Firmware+3 more
Nov 21, 2024
Dec 18, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like capabilities) about the device itself and network settings of the devic...Show more
An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker to retrieve information (like capabilities) about the device itself and network settings of the device, disclosing possibly internal network settings if the device is connected to the internet.Show less
1Adobe
1Experience Manager
Sep 19, 2025
Dec 15, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application....Show more
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application. Exploitation of this issue does not require user interaction.Show less
1Microsoft
1Azure Devops Server
Nov 21, 2024
Dec 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Azure DevOps Server Spoofing Vulnerability
1Primx
3Zed!
ZedmailZonecentral
Jun 3, 2025
Dec 13, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualif...Show more
ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; ZED! for Windows, Mac, Linux before 2023.5; ZEDFREE for Windows, Mac, Linux before 2023.5; or ZEDPRO for Windows, Mac, Linux before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger network access to an attacker-controlled computer when opened by the victim.Show less
1Codeastro
1Pos And Inventory Management System
Nov 21, 2024
Dec 13, 2023
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /accounts_con/register_account of...Show more
A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /accounts_con/register_account of the component User Creation Handler. The manipulation of the argument account_type with the input Admin leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247909 was assigned to this vulnerability.Show less
1Thecosy
1Icecms
Nov 21, 2024
Dec 13, 2023
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper access...Show more
A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247889 was assigned to this vulnerability.Show less
1Thecosy
1Icecms
Nov 21, 2024
Dec 13, 2023
N/A· v4
4.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads...Show more
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247886 is the identifier assigned to this vulnerability.Show less
1Silverpeas
1Silverpeas
May 22, 2025
Dec 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or perm...Show more
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.Show less
1Fortinet
2Fortios
Fortiproxy
Nov 21, 2024
Dec 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below ma...Show more
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP database update.Show less
1Relyum
1Rely Pcie Firmware
Nov 21, 2024
Dec 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.
1Mattermost
1Mattermost Server
Nov 21, 2024
Dec 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook....Show more
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team.  Show less
1Mattermost
1Mattermost Server
Nov 21, 2024
Dec 12, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.
1Huawei
1Ar617vw Firmware
Nov 21, 2024
Dec 12, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information.
1Softwareag
1Webmethods
Nov 21, 2024
Dec 7, 2023
N/A· v4
6.5 MEDIUM· v3
7.5 HIGH· v2
A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. It is p...Show more
A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. It is possible to launch the attack remotely. To access a file like /assets/ a popup may request username and password. By just clicking CANCEL you will be redirected to the directory. If you visited /invoke/wm.server/connect, you'll be able to see details like internal IPs, ports, and versions. In some cases if access to /assets/ is refused, you may enter /assets/x as a wrong value, then come back to /assets/ which we will show the requested data. It appears that insufficient access control is depending on referrer header data. VDB-247158 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Pleasanter
1Pleasanter
May 28, 2025
Dec 6, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other users who are not permitted to access.
1Qemu
1Qemu
Nov 21, 2024
Dec 6, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exporte...Show more
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.Show less
1Qualcomm
13Qca6574 Firmware
Qca6574a FirmwareQca6574au Firmware+10 more
Nov 21, 2024
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption in Automotive OS whenever untrusted apps try to access HAb for graphics functionalities.