← Back
CWE-284

7,464 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nextcloud
1Nextcloud
Jun 17, 2026
May 20, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could r...Show more
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information. Nextcloud Android version 3.19.0 contains a patch for this issue. There are no known workarounds available.Show less
1Hcltech
1Domino
Jun 17, 2026
May 19, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or...Show more
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.Show less
1Jfrog
1Artifactory
Jun 17, 2026
May 19, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for P...Show more
JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit and delete Repository Layouts while Repository Layouts configuration should only be available for Platform Administrators.Show less
1Nvidia
2Gpu Display Driver
Virtual Gpu
Jun 17, 2026
May 17, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged register...Show more
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.Show less
1Solarwinds
1Serv U
Jun 17, 2026
May 17, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify t...Show more
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only operation). This UAC issue leads to a data leak to unauthorized users for a domain, with no log of them accessing the data unless they attempt to modify it. This read-only activity is logged to the original domain and does not specify which domain was accessed.Show less
1Wowonder
1Wowonder
Jun 17, 2026
May 17, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting message...Show more
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.Show less
1Weintek
16Cmt Ctrl01 Firmware
Cmt Fhd FirmwareCmt G01 Firmware+13 more
Jun 17, 2026
May 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on beha...Show more
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.Show less
1Publify Project
1Publify
Jun 17, 2026
May 16, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected art...Show more
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising confidentiality and integrity of users.Show less
1Publify Project
1Publify
Jun 17, 2026
May 16, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
1Sonicwall
5Sma 6200 Firmware
Sma 6210 FirmwareSma 7200 Firmware+2 more
Jun 17, 2026
May 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.
1Myscada
1Mypro
Jun 17, 2026
May 13, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
1Inhandnetworks
1Inrouter302 Firmware
Jun 17, 2026
May 12, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send...Show more
A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.Show less
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
May 10, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Windows Address Book Remote Code Execution Vulnerability
1Wpgraphql
1Wpgraphql
Jun 17, 2026
May 9, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the ac...Show more
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.Show less
1Microweber
1Microweber
Jun 17, 2026
May 9, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account...Show more
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows an attacker to gain pre-authentication to the victim’s account. Further, due to the lack of proper validation of email coming from Social Login and failing to check if an account already exists, the victim will not identify if an account is already existing. Hence, the attacker’s persistence will remain. An attacker would be able to see all the activities performed by the victim user impacting the confidentiality and attempt to modify/corrupt the data impacting the integrity and availability factor. This attack becomes more interesting when an attacker can register an account from an employee’s email address. Assuming the organization uses G-Suite, it is much more impactful to hijack into an employee’s account.Show less
1Cisco
1Enterprise Nfv Infrastructure Software
Jun 17, 2026
May 4, 2022
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level,...Show more
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Enterprise Nfv Infrastructure Software
Jun 17, 2026
May 4, 2022
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level,...Show more
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
1Enterprise Nfv Infrastructure Software
Jun 17, 2026
May 4, 2022
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level,...Show more
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent a...Show more
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.Show less
1Shortpixel
1Shortpixel Adaptive Images
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.