CWE-284
7,471 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,471)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Online Food Ordering System Project Oretnom232Online Food Ordering System Online Food Ordering SystemJun 17, 2026 Mar 16, 2023 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /fos/admin/ajax.php?action=save_settings of the com...Show more |
1Microfocus 1Netiq Advanced Authentication Jun 17, 2026 Mar 15, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2 |
1Sap 1Netweaver Application Server For Java Jun 17, 2026 Mar 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and dir...Show more |
1Sap 1Netweaver Application Server For Java Jun 17, 2026 Mar 14, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity
|
In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items |
An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room. |
1Qualcomm 25Qam8295p Firmware Qca6574au FirmwareQca6696 Firmware+22 moreJun 17, 2026 Mar 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory corruption in Automotive Android OS due to improper validation of array index. |
An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO en...Show more |
1Feiqu Opensource Project 1Feiqu Opensource Jun 17, 2026 Mar 8, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 feiqu-opensource Background Vertical authorization vulnerability exists in IndexController.java. demo users with low permission can perform operations within the permission of the admin super administrator and can use th...Show more |
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests. |
1Dos Osaka 2Rakuraku Pc Cloud Agent Ss1Jun 17, 2026 Mar 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to bypass access restriction and download an arbitrary file of the directo...Show more |
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, a...Show more |
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10....Show more |
XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro doe...Show more |
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors. |
The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app may be able to bypass Privacy preferences. |
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to bypass Privacy preferences. |
Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improper Access Control. Secure view for internal shares can be circumvented...Show more |
A vulnerability was found in Twister Antivirus 8.17. It has been declared as critical. This vulnerability affects the function 0x801120E4 in the library filmfd.sys of the component IoControlCode Handler. The manipulation...Show more |
1Alphaware Simple E Commerce System Project 1Alphaware Simple E Commerce System Jun 17, 2026 Feb 24, 2023 N/A· v4 5.3 MEDIUM· v3 6.4 MEDIUM· v2 A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file /alphaware/summary.php of the component Payment Handler. The manipu...Show more |