← Back
CWE-284

7,464 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
Jun 23, 2026
Aug 5, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
1Tooljet
1Tooljet
Jun 17, 2026
Aug 2, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
1Pandorafms
1Pandora Fms
Jun 17, 2026
Aug 1, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intende...Show more
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.Show less
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Jul 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This issue affects some unknown processing of the file /php_action/createUser.php. The manipulation leads...Show more
A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This issue affects some unknown processing of the file /php_action/createUser.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Zulip
1Zulip
Nov 21, 2024
Jul 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
1Zulip
1Zulip
Nov 21, 2024
Jul 28, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.
1Visam
1Vbase Web Remote
Jun 17, 2026
Jul 27, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.
1Cloudflare
1Warp
Jun 17, 2026
Jul 26, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such a...Show more
By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such as 'Lock WARP switch'.Show less
1Givewp
1Givewp
Jun 17, 2026
Jul 21, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
1Oracle
1Banking Trade Finance
Jun 17, 2026
Jul 19, 2022
N/A· v4
6.4 MEDIUM· v3
N/A· v2
Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows l...Show more
Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).Show less
4Debian
FedoraprojectNodejs+1 more
4Debian Linux
FedoraNode.js+1 more
Jun 17, 2026
Jul 14, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP addr...Show more
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.Show less
1Argoproj
1Argo Cd
Jun 17, 2026
Jul 12, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level.
1Samsung
1Samsung Gallery
Jun 17, 2026
Jul 12, 2022
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using S Pen air gesture.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHA...Show more
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.Show less
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_E...Show more
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.Show less
1Google
1Android
Jun 17, 2026
Jul 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.
1Mendix
1Mendix
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14....Show more
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.2), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12). In case of access to an active user session in an application that is built with an affected version, it’s possible to change that user’s password bypassing password validations within a Mendix application. This could allow to set weak passwords.Show less
1Cisco
3Unified Communications Manager
Unified Communications Manager Im And Presence ServiceUnity Connection
Jun 17, 2026
Jul 6, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), and Cisco Unity Connection co...Show more
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to insufficient access control checks on the affected device. An attacker with read-only privileges could exploit this vulnerability by executing a specific vulnerable command on an affected device. A successful exploit could allow the attacker to perform a set of administrative actions they should not be able to.Show less
1Jetbrains
1Hub
Jun 17, 2026
Jul 1, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services