← Back
CWE-284

7,479 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
7Windows 10 1809
Windows 10 21h2Windows 10 22h2+4 more
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Win32k Elevation of Privilege Vulnerability
1Microsoft
1Windows Server 2008
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
1Microsoft
7Windows 10 1809
Windows 10 21h2Windows 10 22h2+4 more
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Kernel Elevation of Privilege Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
Oct 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Active Directory Domain Services Information Disclosure Vulnerability
1Microsoft
1Azure Devops Server
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Azure DevOps Server Elevation of Privilege Vulnerability
1Fortinet
1Fortimanager
Jun 17, 2026
Oct 10, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authentica...Show more
An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device management" permission on his profile and belonging to a specific ADOM to add and delete CLI script on other ADOMsShow less
1Fortinet
1Fortios
Jun 17, 2026
Oct 10, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host.
1Siemens
5Simatic Cp 1604 Firmware
Simatic Cp 1616 FirmwareSimatic Cp 1623 Firmware+2 more
Jun 17, 2026
Oct 10, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). The kernel memory of...Show more
A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). The kernel memory of affected devices is exposed to user-mode via direct memory access (DMA) which could allow a local attacker with administrative privileges to execute arbitrary code on the host system without any restrictions.Show less
1Hp
1Life
Jun 17, 2026
Oct 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.
1Objectcomputing
1Micronaut Security
Jun 17, 2026
Oct 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if toke...Show more
Micronaut Security is a security solution for applications. Prior to versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1, IdTokenClaimsValidator skips `aud` claim validation if token is issued by same identity issuer/provider. Any OIDC setup using Micronaut where multiple OIDC applications exists for the same issuer but token auth are not meant to be shared. This issue has been patched in versions 3.1.2, 3.2.4, 3.3.2, 3.4.3, 3.5.3, 3.6.6, 3.7.4, 3.8.4, 3.9.6, 3.10.2, and 3.11.1. Show less
1Sick
1Apu0200 Firmware
Jun 17, 2026
Oct 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
1Decidim
1Decidim
Jun 17, 2026
Oct 6, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correc...Show more
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys. This issue has been patched in version 0.26.8 and 0.27.4.Show less
1Dell
1Smartfabric Storage Software
Jun 17, 2026
Oct 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to abili...Show more
Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbritrary shell commands. Show less
2Candlepinproject
Redhat
2Candlepin
Satellite
Jun 17, 2026
Oct 4, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
1Nokia
6Wavelite Metro 200 And F2b Fans Firmware
Wavelite Metro 200 And Fan FirmwareWavelite Metro 200 Ne And F2b Fans Firmware+3 more
Jun 17, 2026
Oct 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Me...Show more
If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro 200 OPS and F2B fans, WaveLite Metro 200 NE and F2B fans, and WaveLite Metro 200 NE OPS and F2B fans.Show less
1Bydemes
1Airspace Cctv Web Service
Jun 17, 2026
Oct 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privilege...Show more
The web service of ByDemes Group Airspace CCTV Web Service in its 2.616.BY00.11 version, contains a privilege escalation vulnerability, detected in the Camera Control Panel, whose exploitation could allow a low-privileged attacker to gain administrator access.Show less
1Salesagility
1Suitecrm
Jun 17, 2026
Oct 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
1Qualcomm
42Ar8035 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+39 more
Jun 17, 2026
Oct 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range.
1Qualcomm
161Aqt1000 Firmware
Ar8035 FirmwareFastconnect 6200 Firmware+158 more
Jun 17, 2026
Oct 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Access to the VM resource manager can lead to Memory Corruption.
1Purestorage
1Purity//fa
Jun 17, 2026
Oct 3, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.