CWE-284
7,464 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,464)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ecoa 3Ecs Router Controller Ecs Firmware Riskbuster FirmwareRiskterminatorJun 17, 2026 Sep 30, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers with gen...Show more |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1420 Gateway FirmwareWireless 1552wu Gateway FirmwareJun 17, 2026 Sep 29, 2021 N/A· v4 10.0 CRITICAL· v3 6.8 MEDIUM· v2 There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in expo...Show more |
1Sonicwall 5Sma 200 Firmware Sma 210 FirmwareSma 400 Firmware+2 moreJun 17, 2026 Sep 27, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. |
1Citrix 1Sharefile Storagezones Controller Jun 17, 2026 Sep 23, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller. |
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must...Show more |
A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability...Show more |
A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulner...Show more |
1Cisco 411100 8p Firmware 1120 Firmware1160 Firmware+38 moreJun 17, 2026 Sep 23, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vul...Show more |
1Bootstrapped 1Visual Link Preview Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscrib...Show more |
1Motopress 1Timetable And Event Schedule Jun 17, 2026 Sep 20, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot fr...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Sep 14, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The affected software allows sending send-to-sleep notifications to the managed devices. An unauthenticated attacker in the s...Show more |
Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview. |
An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a guest user to elevate privileges to the Administrator using this vulnerabil...Show more |
Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page. |
A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected...Show more |
A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arb...Show more |
1Cisco 2Application Policy Infrastructure Controller Cloud Application Policy Infrastructure ControllerJun 17, 2026 Aug 25, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack...Show more |
1Cisco 2Application Policy Infrastructure Controller Cloud Application Policy Infrastructure ControllerJun 17, 2026 Aug 25, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack...Show more |
1Cisco 2Application Policy Infrastructure Controller Cloud Application Policy Infrastructure ControllerJun 17, 2026 Aug 25, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to...Show more |
1Dolibarr 2Dolibarr Dolibarr Erp/crmJun 17, 2026 Aug 17, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. Th...Show more |