CWE-284
7,824 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,824)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large nu...Show more |
1Streamax 1Streamax Crocus Jun 17, 2026 Oct 17, 2025 2.1 LOW· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the file /FileDir.do?Action=Upload. Performing manipulation of the argument Fi...Show more |
A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administr...Show more |
A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Executing a manipulation can lead to improper access controls. The attack...Show more |
Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, Strapi reflects the value of the Origin hea...Show more |
A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent via email. An attacker can m...Show more |
Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker...Show more |
1Wso2 15Api Control Plane Api ManagerApi Manager Analytics+12 moreJun 17, 2026 Oct 16, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this fl...Show more |
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data. |
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Oct 14, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally. |
1Microsoft 11Windows 10 1809 Windows 10 21h2Windows 10 22h2+8 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally. |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. |
1Microsoft 1Azure Connected Machine Agent Jun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. |
1Microsoft 16Windows 10 1507 Windows 10 1607Windows 10 1809+13 moreJun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
1Microsoft 3Windows 11 24h2 Windows 11 25h2Windows Server 2025Jun 17, 2026 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
1Microsoft 3Visual Studio 2017 Visual Studio 2019Visual Studio 2022Jun 17, 2026 Oct 14, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. |
An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users. |