CWE-284
5,081 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,081)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Nextcloud2Fedora Group FoldersNov 21, 2024 May 12, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name. |
1Cisco 3Integrated Management Controller Supervisor Ucs DirectorUcs Director Express For Big DataNov 21, 2024 May 6, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attac...Show more |
1Cisco 1Secure Firewall Management Center Nov 26, 2024 May 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data on an affected d...Show more |
1Cisco 1Firepower Threat Defense Nov 21, 2024 May 6, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. T...Show more |
1Cisco 13Asa 5505 Firmware Asa 5510 FirmwareAsa 5512 X Firmware+10 moreNov 21, 2024 May 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an a...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Application Platform Continuous DeliveryOpenshift Application Runtimes+1 moreNov 21, 2024 May 4, 2020 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead t...Show more |
1Ui 2Unifi Cloud Key Gen2 Firmware Unifi Cloud Key Gen2 Plus FirmwareNov 21, 2024 May 2, 2020 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 UniFi Cloud Key firmware <= v1.1.10 for Cloud Key gen2 and Cloud Key gen2 Plus contains a vulnerability that allows unrestricted root access through the serial interface (UART). |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Apr 30, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been patched in version 5.4.1, along with all the...Show more |
1Inductiveautomation 1Ignition Gateway Nov 21, 2024 Apr 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk space on the Ignition...Show more |
In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific prices. The problem is fixed in 1.7.6.5. |
"In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there is improper access controls on product attributes page. The problem is fixed in 1.7.6.5. |
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5. |
In PrestaShop between versions 1.5.0.0 and 1.7.6.5, there are improper access control since the the version 1.5.0.0 for legacy controllers. - admin-dev/index.php/configure/shop/customer-preferences/ - admin-dev/index.php...Show more |
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attacker...Show more |
vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes w...Show more |
Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker to affect the integrity of the application. The vulnerability is due to improper validation of host h...Show more |
1Mh Wikibot Project 1Mh Wikibot Nov 21, 2024 Apr 7, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access the steward commands on the IRC interface by impersonating the Nickname used by a privileged user as n...Show more |
Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerNov 21, 2024 Mar 20, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL. |
Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line utility. |