CWE-284
7,824 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,824)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new folders, up- and download files as a ZIP...Show more |
1Primakon 1Project Contract Management Jun 17, 2026 Nov 25, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of weak access controls any low level user ca...Show more |
1Primakon 1Project Contract Management Jun 17, 2026 Nov 25, 2025 N/A· v4 8.6 HIGH· v3 N/A· v2 Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing unauthenticated attackers to perform PO...Show more |
1Desktopalert 1Pingalert Application Server Jun 17, 2026 Nov 24, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Incorrect Access Control, leading to Remote Information Disclosure. |
1Desktopalert 1Pingalert Application Server Jun 17, 2026 Nov 24, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes. |
1Millensys 1Vision Tools Workspace Jun 17, 2026 Nov 24, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authentication. This page leaks plaintext database credentials, file share paths, in...Show more |
1Fabian 1Online Bidding System Jun 17, 2026 Nov 24, 2025 2.0 LOW· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestr...Show more |
1Projectworlds 1Advanced Library Management System Jun 17, 2026 Nov 24, 2025 2.1 LOW· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_book.php. The manipulation of the argument image results in unrestricte...Show more |
1Ashraf Kabir 1Travel Agency Jun 17, 2026 Nov 23, 2025 2.1 LOW· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestri...Show more |
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to override managed Wi-Fi profiles. |
Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only...Show more |
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. |
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionali...Show more |
phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting user-controlled parameters ('...Show more |
A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access co...Show more |
1Campcodes 1Retro Basketball Shoes Online Store Jun 17, 2026 Nov 20, 2025 2.0 LOW· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lea...Show more |
1Campcodes 1Retro Basketball Shoes Online Store Jun 17, 2026 Nov 19, 2025 2.0 LOW· v4 9.8 CRITICAL· v3 5.8 MEDIUM· v2 A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipulation of the argument...Show more |
An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauthorized attackers to delete and create arbitrary accounts. |
1Axeltechnology 1Streamermax Mk Ii Firmware Jun 17, 2026 Nov 19, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attacke...Show more |
The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi-bin/gstFcgi.fcgi endpoint. Unauthenticated remote attackers can list u...Show more |