CWE-284
7,480 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,480)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intel 1Aptio V Uefi Firmware Integrator Tools Jun 17, 2026 Nov 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access. |
1Intel 4Optane Memory H20 With Solid State Storage Firmware Optane Ssd 905p FirmwareOptane Ssd Dc P4800x Firmware+1 moreJun 17, 2026 Nov 14, 2023 N/A· v4 4.6 MEDIUM· v3 N/A· v2 Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access. |
Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access. |
Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. |
Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access. |
Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 1Aptio V Uefi Firmware Integrator Tools Jun 17, 2026 Nov 14, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access. |
1Intel 1Aptio V Uefi Firmware Integrator Tools Jun 17, 2026 Nov 14, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access. |
An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next...Show more |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 21h2+8 moreJun 17, 2026 Nov 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Kernel Information Disclosure Vulnerability |
An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate t...Show more |
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access...Show more |
A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to. |
Incorrect access control in the AdHoc User creation form of eMudhra emSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user. |
Attacker can perform a Denial of Service attack to crash the ICAS 3 IVI ECU in a Volkswagen ID.3 (and other vehicles of the VW Group with the same hardware) and spoof volume setting commands to irreversibly turn on audio...Show more |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Students in "Only see own membership" groups could see other students in the group, which should be hidden. |
1Prestashop 1Customer Reassurance Block Jun 17, 2026 Nov 9, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the config...Show more |