← Back
CWE-284

7,464 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Exposure Notification Verification Server
Jun 17, 2026
Dec 9, 2021
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notifica...Show more
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.Show less
1Ivanti
1Avalanche
Jun 17, 2026
Dec 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
1Solarwinds
1Serv U
Jun 17, 2026
Dec 6, 2021
N/A· v4
6.8 MEDIUM· v3
6.8 MEDIUM· v2
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
1Amd
1Amd Uprof
Jun 17, 2026
Dec 1, 2021
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.
1Insulet
1Omnipod Insulin Management System Firmware
Jun 17, 2026
Dec 1, 2021
N/A· v4
8.1 HIGH· v3
4.8 MEDIUM· v2
Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communicati...Show more
Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.Show less
1Kimai2 Project
1Kimai2
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
kimai2 is vulnerable to Improper Access Control
1Bookstackapp
1Bookstack
Jun 17, 2026
Nov 30, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
bookstack is vulnerable to Improper Access Control
1Businessdnasolutions
1Topease
Jun 17, 2026
Nov 30, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functio...Show more
Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for higher privileged users, via identifying said components in the front-end source code or other means.Show less
1Wpwave
1Hide My Wp
Jun 17, 2026
Nov 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
1Bitdefender
2Endpoint Security Tools
Gravityzone
Jun 17, 2026
Nov 24, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches....Show more
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for Linux as a relay role allows an attacker to manipulate the remote address used for pulling patches. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.6.27.390; versions prior to 7.1.2.33. Bitdefender Unified Endpoint versions prior to 6.2.21.160. Bitdefender GravityZone versions prior to 6.24.1-1.Show less
1Philips
2Mri 1.5t Firmware
Mri 3t Firmware
Jun 17, 2026
Nov 19, 2021
5.9 MEDIUM· v4
5.5 MEDIUM· v3
5.0 MEDIUM· v2
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
1Cisco
1Common Services Platform Collector
Jun 17, 2026
Nov 19, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due...Show more
A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog configuration. An attacker could exploit this vulnerability by configuring non-log files as sources for syslog reporting through the web application. A successful exploit could allow the attacker to read non-log files on the CSPC.Show less
1Webfactoryltd
1Wp Reset Pro
Jun 17, 2026
Nov 18, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete w...Show more
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.Show less
1Brainstormforce
1Starter Templates
Jun 17, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-e...Show more
On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft and host a block containing malicious JavaScript on a server they controlled, and then use it to overwrite any post or page by sending an AJAX request with the action set to astra-page-elementor-batch-process and the url parameter pointed to their remotely-hosted malicious block, as well as an id parameter containing the post or page to overwrite. Any post or page that had been built with Elementor, including published pages, could be overwritten by the imported block, and the malicious JavaScript in the imported block would then be executed in the browser of any visitors to that page.Show less
1Hitachienergy
2Counterparty Settlements And Billing
Retail Operations
Jun 17, 2026
Nov 17, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Jav...Show more
Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.Show less
1Qr Redirector Project
1Qr Redirector
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscribe...Show more
The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector settings via the qr_save_bulk AJAX action, which could allow any authenticated user, such as subscriber to change the redirect response status code of arbitrary QR RedirectsShow less
1Amd
44Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+41 more
Jun 17, 2026
Nov 16, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 10, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hos...Show more
An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this vulnerability enables an attacker to perform any operations allowed by the EC2 role in AWS. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20 VM-Series firewalls; PAN-OS 9.1 versions earlier than PAN-OS 9.1.11 VM-Series firewalls; PAN-OS 9.0 versions earlier than PAN-OS 9.0.14 VM-Series firewalls; PAN-OS 10.0 versions earlier than PAN-OS 10.0.8 VM-Series firewalls. Prisma Access customers are not impacted by this issue.Show less
1Vivo
1Jovi Smart Scene
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.
1Phoenix Media Rename Project
1Phoenix Media Rename
Jun 17, 2026
Nov 8, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones...Show more
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.Show less