CWE-284
7,497 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,497)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted. |
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted. |
An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager. |
An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request. |
Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area. |
Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged attacker could potentially exploit this vulner...Show more |
1Acurax 1Under Construction / Maintenance Mode Jun 17, 2026 Feb 28, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST API. This makes it possible for unauthenti...Show more |
1Brandonwamboldt 1Wordpress Access Control Jun 17, 2026 Feb 28, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to by...Show more |
1Envothemes 1Envo's Elementor Templates & Widgets For Woocommerce Jun 17, 2026 Feb 28, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the templates_ajax_request function in all versions up...Show more |
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid...Show more |
Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted access to the system prior to the attack. It is worth noting that...Show more |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerabi...Show more |
1Intel 4Ethernet Adapter Complete Driver Ethernet Controller I225 It FirmwareEthernet Controller I225 Lm Firmware+1 moreJun 17, 2026 Feb 23, 2024 N/A· v4 8.4 HIGH· v3 N/A· v2 Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Codeastro 1Simple Voting System Jun 17, 2026 Feb 23, 2024 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file users.php of the component Backend. The manipulation leads to...Show more |
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it poss...Show more |
1Carmelo 1Agro School Management System Jun 17, 2026 Feb 22, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control. |
Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access to API information that should only be...Show more |
A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a repository that belongs to an internal service on an affected devic...Show more |
1Keerti1924 1Php Mysql User Signup Login System Jun 17, 2026 Feb 21, 2024 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. The manipulation leads to imprope...Show more |
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Bluetooth. |