CWE-284
7,617 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized exter...Show more |
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh...Show more |
1Intel 2Arc A Graphics Iris Xe GraphicsJun 17, 2026 Aug 14, 2024 5.1 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access. |
1Intel 1Aptio V Uefi Firmware Integrator Tools Jun 17, 2026 Aug 14, 2024 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. |
improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access. |
1Intel 1Ethernet 800 Series Controllers Driver Jun 17, 2026 Aug 14, 2024 9.3 CRITICAL· v4 8.8 HIGH· v3 N/A· v2 Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local...Show more |
1Intel 1Computing Improvement Program Jun 17, 2026 Aug 14, 2024 6.8 MEDIUM· v4 5.5 MEDIUM· v3 N/A· v2 Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of service via local access. |
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage...Show more |
1Microsoft 4Windows 10 21h2 Windows 10 22h2Windows 11 21h2+1 moreJun 17, 2026 Aug 14, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Update Stack Elevation of Privilege Vulnerability |
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreJun 17, 2026 Aug 13, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Windows Initial Machine Configuration Elevation of Privilege Vulnerability |
Azure CycleCloud Remote Code Execution Vulnerability |
1Microsoft 1Azure Connected Machine Agent Jun 17, 2026 Aug 13, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Azure Connected Machine Agent Elevation of Privilege Vulnerability |
Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of s...Show more |
An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the unde...Show more |
1Siemens 1Sinec Traffic Analyzer Jun 17, 2026 Aug 13, 2024 7.6 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated att...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Aug 13, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might injec...Show more |
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, writ...Show more |
1Redhat 2Openshift Ai Openshift Data ScienceJun 17, 2026 Aug 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models wit...Show more |
1Oretnom23 1Computer Laboratory Management System Jun 17, 2026 Aug 12, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories. |
A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete...Show more |