← Back
CWE-284

7,479 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Nov 8, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.
1Boltwire
1Boltwire
Jun 17, 2026
Nov 7, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.
1Samsung
1Push Service
Jun 17, 2026
Nov 7, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device.
1Samsung
1Account
Jun 17, 2026
Nov 7, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.
1Microweber
1Microweber
Jun 17, 2026
Nov 7, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Access Control in GitHub repository microweber/microweber prior to 2.0.
1Vaerys Dawn
1Discordsailv2
Nov 21, 2024
Nov 6, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper ac...Show more
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to address this issue. The name of the patch is cc12e0be82a5d05d9f359ed8e56088f4f8b8eb69. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-244484.Show less
1Vaerys Dawn
1Discordsailv2
Nov 21, 2024
Nov 5, 2023
N/A· v4
9.8 CRITICAL· v3
5.2 MEDIUM· v2
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation...Show more
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to address this issue. The patch is named cc12e0be82a5d05d9f359ed8e56088f4f8b8eb69. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244483.Show less
1Nationaledtech
1Boomerang
Jun 17, 2026
Nov 3, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal me...Show more
An issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the android:allowBackup="false" attribute in the manifest. This allows the user to backup the internal memory of the app to a PC. This gives the user access to the API token that is used to authenticate requests to the API.Show less
1Nvidia
1Virtual Gpu
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering.
1Nvidia
1Virtual Gpu
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client,...Show more
NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.Show less
1Sangoma
1Freepbx
Jul 9, 2026
Nov 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.
1Dashy
1Dashy
Jun 17, 2026
Nov 2, 2023
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /config-manager/save of the component Configuration Handler. The manipulation of the argument config...Show more
A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /config-manager/save of the component Configuration Handler. The manipulation of the argument config leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-244305 was assigned to this vulnerability.Show less
1Cisco
2Firepower Threat Defense
Secure Firewall Threat Defense
Aug 11, 2026
Nov 1, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation...Show more
A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by spoofing an IP address until they bypass the restriction. A successful exploit could allow the attacker to bypass location-based IP address restrictions.Show less
1Mintplexlabs
1Anythingllm
Jun 17, 2026
Oct 30, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.
1Abus
47Tvip 10000 Firmware
Tvip 10001 FirmwareTvip 10005 Firmware+44 more
Nov 21, 2024
Oct 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.
1Sielco
3Polyeco1000 Firmware
Polyeco300 FirmwarePolyeco500 Firmware
Jun 17, 2026
Oct 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative...Show more
Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges. Show less
1Sielco
3Polyeco1000 Firmware
Polyeco300 FirmwarePolyeco500 Firmware
Jun 17, 2026
Oct 26, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers c...Show more
Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources behind protected pages. Show less
1Sielco
3Polyeco1000 Firmware
Polyeco300 FirmwarePolyeco500 Firmware
Jun 17, 2026
Oct 26, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without...Show more
Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. Show less
1Sielco
3Polyeco1000 Firmware
Polyeco300 FirmwarePolyeco500 Firmware
Jun 17, 2026
Oct 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this via a specially crafted request to gain acc...Show more
Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this via a specially crafted request to gain access to sensitive information. Show less
1Sielco
3Polyeco1000 Firmware
Polyeco300 FirmwarePolyeco500 Firmware
Jun 17, 2026
Oct 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.