← Back
CWE-284

5,090 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Axcora
1Axcora
Mar 18, 2025
Feb 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.
1Zyxel
2Lte3202 M437 Firmware
Lte3316 M604 Firmware
Nov 21, 2024
Feb 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this v...Show more
A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected device using Telnet.Show less
1Auto Dealer Management System Project
1Auto Dealer Management System
Nov 21, 2024
Feb 19, 2023
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads...Show more
A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221491.Show less
1Adobe
1Connect
Nov 21, 2024
Feb 17, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to...Show more
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.Show less
1Moodle
1Moodle
Nov 21, 2024
Feb 17, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to ga...Show more
The vulnerability was found Moodle which exists due to insufficient limitations on the "start page" preference. A remote attacker can set that preference for another user. The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.Show less
1Citrix
1Workspace
Mar 19, 2025
Feb 16, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
1Citrix
1Workspace
Mar 18, 2025
Feb 16, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
1Joomla
1Joomla
Oct 24, 2025
Feb 16, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
1Niter
1Niterforum
Mar 19, 2025
Feb 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controller/AdminController.java, allows attackers to gain escalated privileges.
1Ls Electric
1Xbc Dn32u Firmware
Nov 21, 2024
Feb 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC o...Show more
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol. Show less
1Ls Electric
1Xbc Dn32u Firmware
Nov 21, 2024
Feb 15, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the feature to lock users out of reading data from...Show more
LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the feature to lock users out of reading data from the device. Show less
1Amperecomputing
2Ampere Altra Firmware
Ampere Altra Max Firmware
Mar 19, 2025
Feb 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.
1Google
1Android
Mar 19, 2025
Feb 15, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed....Show more
In permissions of AndroidManifest.xml, there is a possible way to grant signature permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244216503Show less
1Microsoft
1Azure App Service On Azure Stack
Nov 21, 2024
Feb 14, 2023
N/A· v4
8.7 HIGH· v3
N/A· v2
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
1Microsoft
3Sharepoint Enterprise Server
Sharepoint FoundationSharepoint Server
Nov 21, 2024
Feb 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Microsoft SharePoint Server Elevation of Privilege Vulnerability
1Timescale
1Timescaledb
Nov 21, 2024
Feb 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation us...Show more
TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation user. The queries run as part of the telemetry data collection were not run with a locked down `search_path`, allowing malicious users to create functions that would be executed by the telemetry job, leading to privilege escalation. In order to be able to take advantage of this vulnerability, a user would need to be able to create objects in a database and then get a superuser to install TimescaleDB into their database. When TimescaleDB is installed as trusted extension, non-superusers can install the extension without help from a superuser. Version 2.9.3 fixes this issue. As a mitigation, the `search_path` of the user running the telemetry job can be locked down to not include schemas writable by other users. The vulnerability is not exploitable on instances in Timescale Cloud and Managed Service for TimescaleDB due to additional security provisions in place on those platforms.Show less
1Mendix
1Mendix
Nov 21, 2024
Feb 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22....Show more
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.10), Mendix Applications using Mendix 9 (V9.18) (All versions < V9.18.4), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.15). Some of the Mendix runtime API’s allow attackers to bypass XPath constraints and retrieve information using XPath queries that trigger errors.Show less
1Nextcloud
1Nextcloud Server
Nov 21, 2024
Feb 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on pass...Show more
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service slowdown, storage overflow, or cost impact when using external email services. Users should upgrade to Nextcloud Server 25.0.1, 24.0.8, or 23.0.12 or Nextcloud Enterprise Server 25.0.1, 24.0.8, or 23.0.12 to receive a patch. No known workarounds are available.Show less
1Nextcloud
2Nextcloud Server
Richdocuments
Nov 21, 2024
Feb 13, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25....Show more
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, Nextcloud Enterprise Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, and Nextcloud Office (Richdocuments) App 6.x prior to 6.3.1 and 7.x prior to 7.0.1 have previews accessible without a watermark. The download should be hidden and the watermark should get applied. This issue is fixed in Nextcloud Server 25.0.1 and 24.0.8, Nextcloud Enterprise Server 25.0.1 and 24.0.8, and Nextcloud Office (Richdocuments) App 7.0.1 (for 25) and 6.3.1 (for 24). No known workarounds are available.Show less
1Devolutions
1Devolutions Server
Dec 3, 2025
Feb 12, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.