← Back
CWE-284

7,464 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Smartthings
Jun 17, 2026
Oct 7, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.
1Samsung
1Smartthings
Jun 17, 2026
Oct 7, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.
1Samsung
1Smartthings
Jun 17, 2026
Oct 7, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.
1Samsung
1Smartthings
Jun 17, 2026
Oct 7, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
1Samsung
1Smartthings
Jun 17, 2026
Oct 7, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.
1Samsung
1Smartthings
Jun 17, 2026
Oct 7, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
1Samsung
1Smartthings
Jun 17, 2026
Oct 7, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.
1Samsung
1Smartthings
Jun 17, 2026
Oct 7, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.
1Samsung
1Quick Share
Jun 17, 2026
Oct 7, 2022
N/A· v4
3.5 LOW· v3
N/A· v2
Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive information via implicit broadcast.
1Samsung
1Factorycamerafb
Jun 17, 2026
Oct 7, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege.
1Google
1Android
Jun 17, 2026
Oct 7, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.
1Google
1Android
Jun 17, 2026
Oct 7, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.
1Google
1Android
Jun 17, 2026
Oct 7, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.
1Google
1Android
Jun 17, 2026
Oct 7, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
1Google
1Android
Jun 17, 2026
Oct 7, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
1Cisco
26Aironet 1542d Firmware
Aironet 1542i FirmwareAironet 1562d Firmware+23 more
Jun 17, 2026
Sep 30, 2022
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affecte...Show more
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.Show less
1Spsoftmobile
1Applock
Jun 17, 2026
Sep 30, 2022
N/A· v4
6.6 MEDIUM· v3
N/A· v2
AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is possible because the application did not correctly implement fingerprint validations.
1Ibm
1Qradar User Behavior Analytics
Jun 17, 2026
Sep 28, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they should not have access to. IBM X-Force ID: 232791.
1Gajim
1Gajim
Jun 17, 2026
Sep 27, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to be part of the group chat or single chat....Show more
An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to be part of the group chat or single chat. The fixed version is 1.5.0.Show less
1Measuresoft
1Scadapro Server
Jun 17, 2026
Sep 23, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with...Show more
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.Show less