CWE-284
7,464 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,464)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wp Survey Plus Project 1Wp Survey Plus Jun 17, 2026 Nov 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX actions, allowing any user to call them and add/edit/delete Surveys. Furthermore, due to the lack of sa...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Jun 17, 2026 Nov 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download. |
WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting...Show more |
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers. |
1Cisco 5Catalyst Pon Switch Cgp Ont 1p Firmware Catalyst Pon Switch Cgp Ont 4p FirmwareCatalyst Pon Switch Cgp Ont 4pv Firmware+2 moreJun 17, 2026 Nov 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform...Show more |
1Cisco 5Catalyst Pon Switch Cgp Ont 1p Firmware Catalyst Pon Switch Cgp Ont 4p FirmwareCatalyst Pon Switch Cgp Ont 4pv Firmware+2 moreJun 17, 2026 Nov 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform...Show more |
1Cisco 5Catalyst Pon Switch Cgp Ont 1p Firmware Catalyst Pon Switch Cgp Ont 4p FirmwareCatalyst Pon Switch Cgp Ont 4pv Firmware+2 moreJun 17, 2026 Nov 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform...Show more |
1Hashthemes 1Hashthemes Demo Importer Jun 17, 2026 Nov 1, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that tr...Show more |
1Imagesourcecontrol 1Image Source Control Jun 17, 2026 Nov 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit) |
1Jupyterhub 1First Use Authenticator Jun 17, 2026 Oct 28, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0...Show more |
1Cisco 11Adaptive Security Appliance Software Asa 5505 FirmwareAsa 5512 X Firmware+8 moreAug 11, 2026 Oct 27, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the Simple Network Management Protocol version 3 (SNMPv3) access control functionality of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow...Show more |
1Cisco 3Firepower Threat Defense Secure Firewall Management CenterSecure Firewall Threat DefenseAug 11, 2026 Oct 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured ru...Show more |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (49160). An attacker must first obtain the ability to execute low-privileged code on the target guest...Show more |
5Debian FedoraprojectNetapp+2 more5Clustered Data Ontap Communications Diameter Signaling RouterDebian Linux+2 moreJun 17, 2026 Oct 25, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged u...Show more |
The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication. |
1Catchplugins 10Catch Scroll Progress Bar Catch Sticky MenuCatch Themes Demo Import+7 moreJun 17, 2026 Oct 18, 2021 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPres...Show more |
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. |
While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could al...Show more |
1Bostonscientific 1Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware Jun 17, 2026 Oct 4, 2021 N/A· v4 7.6 HIGH· v3 7.2 HIGH· v2 A skilled attacker with physical access to the affected device can gain access to the hard disk drive of the device to change the telemetry region and could use this setting to interrogate or program an implantable devic...Show more |
The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation. |