← Back
CWE-284

5,090 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Royal Elementor Addons
1Royal Elementor Addons
Apr 8, 2026
Jan 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user,...Show more
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_library_template' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import and activate templates from the plugin's template library.Show less
1Royal Elementor Addons
1Royal Elementor Addons
Apr 8, 2026
Jan 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user,...Show more
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_save_template_conditions' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to modify the conditions under which templates are displayed.Show less
1Royal Elementor Addons
1Royal Elementor Addons
Apr 8, 2026
Jan 10, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, inc...Show more
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configuration templates, which can be chosen and imported via a separate action documented in CVE-2022-4704.Show less
1Royal Elementor Addons
1Royal Elementor Addons
Apr 8, 2026
Jan 10, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, inc...Show more
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import preset site configuration templates including images and settings.Show less
1Royal Elementor Addons
1Royal Elementor Addons
Apr 8, 2026
Jan 10, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, in...Show more
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data.Show less
1Royal Elementor Addons
1Royal Elementor Addons
Apr 8, 2026
Jan 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user,...Show more
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it is part of an extremely limited hardcoded selection. This also switches the site to the 'royal-elementor-kit' theme, potentially resulting in availability issues.Show less
1Royal Elementor Addons
1Royal Elementor Addons
Apr 8, 2026
Jan 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user,...Show more
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If no such theme is installed doing so can also impact site availability as the site attempts to load a nonexistent theme.Show less
1Librephotos Project
1Librephotos
Apr 7, 2025
Jan 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
api/views/user.py in LibrePhotos before e19e539 has incorrect access control.
1Sap
1Netweaver Application Server For Java
Nov 21, 2024
Jan 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be us...Show more
An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could allow the attacker to have full read access to user data, make modifications to user data, and make services within the system unavailable.Show less
1Sap
1Host Agent
Nov 21, 2024
Jan 10, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note...Show more
In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are denied the ability to logon locally by security policy so that this can only occur if the system has already been compromised.Show less
1Nextcloud
1Talk
Nov 21, 2024
Jan 9, 2023
N/A· v4
2.1 LOW· v3
N/A· v2
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker n...Show more
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2. Show less
1Weave
1Weave Gitops
Nov 21, 2024
Jan 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a K...Show more
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's resources. GitOps run has a local S3 bucket which it uses for synchronizing files that are later applied against a Kubernetes cluster. Its endpoint had no security controls to block unauthorized access, therefore allowing local users (and processes) on the same machine to see and alter the bucket content. By leveraging this vulnerability, an attacker could pick a workload of their choosing and inject it into the S3 bucket, which resulted in the successful deployment in the target cluster, without the need to provide any credentials to either the S3 bucket nor the target Kubernetes cluster. There are no known workarounds for this issue, please upgrade. This vulnerability has been fixed by commits 75268c4 and 966823b. Users should upgrade to Weave GitOps version >= v0.12.0 released on 08/12/2022. ### Workarounds There is no workaround for this vulnerability. ### References Disclosed by Paulo Gomes, Senior Software Engineer, Weaveworks. ### For more information If you have any questions or comments about this advisory: - Open an issue in [Weave GitOps repository](https://github.com/weaveworks/weave-gitops) - Email us at [support@weave.works](mailto:support@weave.works) Show less
1Reddit On Rails Project
1Reddit On Rails
Nov 21, 2024
Jan 7, 2023
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of the component Vote Handler. The manipulation leads to improper access controls. The attack can be init...Show more
A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of the component Vote Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The patch is identified as 7f3c7407d95d532fcc342b00d68d0ea09ca71030. It is recommended to apply a patch to fix this issue. VDB-217594 is the identifier assigned to this vulnerability.Show less
1Siren
1Investigate
Apr 10, 2025
Jan 5, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Siren Investigate before 12.1.7. There is an ACL bypass on global objects.
1Halcyon Project
1Halcyon
Nov 21, 2024
Jan 4, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the function CBlock::AddToBlockIndex of the file src/main.cpp of the component Block Verification. The m...Show more
A vulnerability has been found in ghostlander Halcyon and classified as critical. Affected by this vulnerability is the function CBlock::AddToBlockIndex of the file src/main.cpp of the component Block Verification. The manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.1.1.0-hal is able to address this issue. The identifier of the patch is 0675b25ae9cc10b5fdc8ea3a32c642979762d45e. It is recommended to upgrade the affected component. The identifier VDB-217417 was assigned to this vulnerability.Show less
1Isode
1M Link
Apr 10, 2025
Jan 1, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LINK-2867.
1Nvidia
2Cloud Gaming
Virtual Gpu
Nov 21, 2024
Dec 30, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the security of the software by gaining privileges, reading sensitive information, or ex...Show more
NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the security of the software by gaining privileges, reading sensitive information, or executing commands.Show less
1Usememos
1Memos
Nov 21, 2024
Dec 28, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
1Usememos
1Memos
Nov 21, 2024
Dec 28, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
1Usememos
1Memos
Nov 21, 2024
Dec 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.