← Back
CWE-284

7,617 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Corydolphin
1Flask Cors
Jun 17, 2026
Aug 18, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized exter...Show more
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.Show less
1Totolink
1Lr350 Firmware
Jun 17, 2026
Aug 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh...Show more
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.Show less
1Intel
2Arc A Graphics
Iris Xe Graphics
Jun 17, 2026
Aug 14, 2024
5.1 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access.
1Intel
1Aptio V Uefi Firmware Integrator Tools
Jun 17, 2026
Aug 14, 2024
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Agilex 7 Fpga Firmware
Jun 17, 2026
Aug 14, 2024
8.5 HIGH· v4
7.9 HIGH· v3
N/A· v2
improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local access.
1Intel
1Ethernet 800 Series Controllers Driver
Jun 17, 2026
Aug 14, 2024
9.3 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local...Show more
Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Intel
1Computing Improvement Program
Jun 17, 2026
Aug 14, 2024
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of service via local access.
1Adobe
2Commerce
Magento
Jun 17, 2026
Aug 14, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage...Show more
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and disclose minor information. Exploitation of this issue does not require user interaction.Show less
1Microsoft
4Windows 10 21h2
Windows 10 22h2Windows 11 21h2+1 more
Jun 17, 2026
Aug 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Update Stack Elevation of Privilege Vulnerability
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Jun 17, 2026
Aug 13, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Windows Initial Machine Configuration Elevation of Privilege Vulnerability
1Microsoft
1Azure Cyclecloud
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Azure CycleCloud Remote Code Execution Vulnerability
1Microsoft
1Azure Connected Machine Agent
Jun 17, 2026
Aug 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Azure Connected Machine Agent Elevation of Privilege Vulnerability
1Amd
1Uprof
Jun 17, 2026
Aug 13, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of s...Show more
Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.Show less
1Fortinet
1Fortios
Jun 17, 2026
Aug 13, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the unde...Show more
An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass the file integrity checking system.Show less
1Siemens
1Sinec Traffic Analyzer
Jun 17, 2026
Aug 13, 2024
7.6 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated att...Show more
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not have access control for accessing the files. This could allow an authenticated attacker with low privilege's to get access to sensitive information.Show less
1Sap
1Netweaver Application Server Abap
Jun 17, 2026
Aug 13, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might injec...Show more
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.Show less
1Clastix
1Kamaji
Jun 17, 2026
Aug 12, 2024
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, writ...Show more
Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in edge-24.8.2.Show less
1Redhat
2Openshift Ai
Openshift Data Science
Jun 17, 2026
Aug 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models wit...Show more
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models with authentication. However, credentials from one model can be used to access other models and APIs within the same namespace. The exposed ServiceAccount tokens, visible in the UI, can be utilized with oc --token={token} to exploit the elevated view privileges associated with the ServiceAccount, leading to unauthorized access to additional resources.Show less
1Oretnom23
1Computer Laboratory Management System
Jun 17, 2026
Aug 12, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.
1Jayesh
1Online Exam System
Jun 17, 2026
Aug 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete...Show more
A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete valid user accounts via the direct URL access.Show less