CWE-284
7,464 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,464)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which m...Show more |
NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to code execution, compromised integrity, or denial of service. |
Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows authenticated users to view contents of archived channels even when this is denied by system administrat...Show more |
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being fo...Show more |
3Debian FedoraprojectZabbix3Debian Linux FedoraZabbixJun 17, 2026 Jan 13, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configur...Show more |
2Fedoraproject Zabbix2Fedora ZabbixJun 17, 2026 Jan 13, 2022 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permi...Show more |
peertube is vulnerable to Improper Access Control |
1Siemens 4Cp 8000 Master Module With I/o 25/+70 Firmware Cp 8000 Master Module With I/o 40/+70 FirmwareCp 8021 Master Module Firmware+1 moreJun 17, 2026 Jan 11, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP...Show more |
peertube is vulnerable to Improper Access Control |
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data. |
bookstack is vulnerable to Improper Access Control |
1Dart 1Dart Software Development Kit Jun 17, 2026 Jan 5, 2022 N/A· v4 3.5 LOW· v3 3.5 LOW· v2 Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a sourc...Show more |
In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access...Show more |
1Sonicwall 6Sma 100 Firmware Sma 200 FirmwareSma 210 Firmware+3 moreJun 17, 2026 Dec 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data. |
1Thalesgroup 1Sentinel Protection Installer Jun 17, 2026 Dec 20, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges. |
bookstack is vulnerable to Improper Access Control |
1Blocksera 1Image Hover Effects Jun 17, 2026 Dec 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin. |
1User Meta Shortcodes Project 1User Meta Shortcodes Jun 17, 2026 Dec 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as contributor to access other users metadata by specifying the user login as a parameter. This makes th...Show more |
1Improved Include Page Project 1Improved Include Page Jun 17, 2026 Dec 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status which can be used to retrieve arbitrary content. This way, users with a role as low as Contributor c...Show more |
snipe-it is vulnerable to Improper Access Control |