CWE-284
7,464 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,464)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Google 1Exposure Notification Verification Server Jun 17, 2026 Dec 9, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notifica...Show more |
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover. |
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine. |
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user. |
1Insulet 1Omnipod Insulin Management System Firmware Jun 17, 2026 Dec 1, 2021 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communicati...Show more |
kimai2 is vulnerable to Improper Access Control |
bookstack is vulnerable to Improper Access Control |
1Businessdnasolutions 1Topease Jun 17, 2026 Nov 30, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functio...Show more |
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin. |
1Bitdefender 2Endpoint Security Tools GravityzoneJun 17, 2026 Nov 24, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches....Show more |
1Philips 2Mri 1.5t Firmware Mri 3t FirmwareJun 17, 2026 Nov 19, 2021 5.9 MEDIUM· v4 5.5 MEDIUM· v3 5.0 MEDIUM· v2 Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
1Cisco 1Common Services Platform Collector Jun 17, 2026 Nov 19, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due...Show more |
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete w...Show more |
1Brainstormforce 1Starter Templates Jun 17, 2026 Nov 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-e...Show more |
1Hitachienergy 2Counterparty Settlements And Billing Retail OperationsJun 17, 2026 Nov 17, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Jav...Show more |
1Qr Redirector Project 1Qr Redirector Jun 17, 2026 Nov 17, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscribe...Show more |
1Amd 44Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+41 moreJun 17, 2026 Nov 16, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources. |
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hos...Show more |
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission. |
1Phoenix Media Rename Project 1Phoenix Media Rename Jun 17, 2026 Nov 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones...Show more |