CWE-284
7,477 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,477)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.9, 26.0.4, and 27.0.1, unauthenticated users could send a DAV request which revea...Show more |
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, and 27.0.1, a user can access files...Show more |
1Microsoft 1Dynamics 365 Business Central Aug 10, 2026 Aug 8, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability |
Microsoft SharePoint Server Information Disclosure Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreAug 10, 2026 Aug 8, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Windows Group Policy Security Feature Bypass Vulnerability |
Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list...Show more |
1Inventory Management System Project 1Inventory Management System Jun 17, 2026 Aug 6, 2023 N/A· v4 9.8 CRITICAL· v3 4.0 MEDIUM· v2 A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit_update.php of the component Password Handler. The m...Show more |
A vulnerability was found in Ruijie RG-EW1200G 1.0(1)B1P5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/sys/set_passwd of the component Administrator Passw...Show more |
Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to perform add/delete QoS policies which are disabled...Show more |
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can res...Show more |
1Arm 6Arm Compiler Arm Compiler For Embedded FusaArm Compiler For Functional Safety+3 moreJun 17, 2026 Jul 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code. |
A vulnerability classified as problematic has been found in Aures Komet up to 20230509. This affects an unknown part of the component Kiosk Mode. The manipulation leads to improper access controls. It is possible to laun...Show more |
1Oracle 1Peoplesoft Enterprise Peopletools Jun 17, 2026 Jul 18, 2023 N/A· v4 8.4 HIGH· v3 N/A· v2 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated a...Show more |
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1. |
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker...Show more |
1Microsoft 7Windows 10 1809 Windows 10 21h2Windows 10 22h2+4 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
1Siemens 2Simatic Cn 4100 Simatic Cn 4100 FirmwareJun 17, 2026 Jul 11, 2023 N/A· v4 10.0 CRITICAL· v3 N/A· v2 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain adm...Show more |
1Citrix 2Linux Virtual Delivery Agent Virtual Apps And DesktopsJun 17, 2026 Jul 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Users with only access to launch VDA applications can launch an unauthorized desktop
|
1Citrix 1Sharefile Storage Zones Controller Jun 17, 2026 Jul 10, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zo...Show more |
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who...Show more |