← Back
CWE-284

7,464 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nvidia
1Shield Experience
Jun 17, 2026
Jan 18, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which m...Show more
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Information disclosure, loss of Integrity, or possible escalation of privileges.Show less
1Nvidia
1Shield Experience
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to code execution, compromised integrity, or denial of service.
1Mattermost
1Mattermost
Jun 17, 2026
Jan 18, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrat...Show more
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrators by directly accessing the APIs.Show less
1Arista
1Eos
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.1 HIGH· v3
4.9 MEDIUM· v2
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being fo...Show more
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.Show less
3Debian
FedoraprojectZabbix
3Debian Linux
FedoraZabbix
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configur...Show more
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.Show less
2Fedoraproject
Zabbix
2Fedora
Zabbix
Jun 17, 2026
Jan 13, 2022
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permi...Show more
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system levelShow less
1Framasoft
1Peertube
Jun 17, 2026
Jan 11, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
peertube is vulnerable to Improper Access Control
1Siemens
4Cp 8000 Master Module With I/o 25/+70 Firmware
Cp 8000 Master Module With I/o 40/+70 FirmwareCp 8021 Master Module Firmware+1 more
Jun 17, 2026
Jan 11, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP...Show more
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). The web server of the affected system allows access to logfiles and diagnostic data generated by a privileged user. An unauthenticated attacker could access the files by knowing the corresponding download links.Show less
1Framasoft
1Peertube
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
peertube is vulnerable to Improper Access Control
1Philips
1Engage
Jun 17, 2026
Jan 10, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.
1Bookstackapp
1Bookstack
Jun 17, 2026
Jan 6, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
bookstack is vulnerable to Improper Access Control
1Dart
1Dart Software Development Kit
Jun 17, 2026
Jan 5, 2022
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a sourc...Show more
Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.Show less
1If Me
1Ifme
Jun 17, 2026
Dec 29, 2021
N/A· v4
7.3 HIGH· v3
4.9 MEDIUM· v2
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access...Show more
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.Show less
1Sonicwall
6Sma 100 Firmware
Sma 200 FirmwareSma 210 Firmware+3 more
Jun 17, 2026
Dec 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
1Thalesgroup
1Sentinel Protection Installer
Jun 17, 2026
Dec 20, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges.
1Bookstackapp
1Bookstack
Jun 17, 2026
Dec 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
bookstack is vulnerable to Improper Access Control
1Blocksera
1Image Hover Effects
Jun 17, 2026
Dec 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
1User Meta Shortcodes Project
1User Meta Shortcodes
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes th...Show more
The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes the WP instance vulnerable to data extrafiltration, including password hashesShow less
1Improved Include Page Project
1Improved Include Page
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor c...Show more
The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor can gain access to content they are not supposed to.Show less
1Snipeitapp
1Snipe It
Jun 17, 2026
Dec 10, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
snipe-it is vulnerable to Improper Access Control