CWE-284
5,090 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,090)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors. |
1Zyxel 2Lte3202 M437 Firmware Lte3316 M604 FirmwareNov 21, 2024 Feb 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this v...Show more |
1Auto Dealer Management System Project 1Auto Dealer Management System Nov 21, 2024 Feb 19, 2023 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads...Show more |
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to...Show more |
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to ga...Show more |
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. |
A malicious user can cause log files to be written to a directory that they do not have permission to write to. |
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. |
An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controller/AdminController.java, allows attackers to gain escalated privileges. |
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC o...Show more |
LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the feature to lock users out of reading data from...Show more |
1Amperecomputing 2Ampere Altra Firmware Ampere Altra Max FirmwareMar 19, 2025 Feb 15, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex. |
In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed....Show more |
1Microsoft 1Azure App Service On Azure Stack Nov 21, 2024 Feb 14, 2023 N/A· v4 8.7 HIGH· v3 N/A· v2 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerNov 21, 2024 Feb 14, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft SharePoint Server Elevation of Privilege Vulnerability |
TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation us...Show more |
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22....Show more |
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on pass...Show more |
1Nextcloud 2Nextcloud Server RichdocumentsNov 21, 2024 Feb 13, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25....Show more |
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
|