CWE-284
7,462 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,462)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Intuit Lacerte 2017 has Incorrect Access Control. |
1Cisco 1Application Policy Infrastructure Controller Jun 17, 2026 Jul 4, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to...Show more |
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to...Show more |
Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted att...Show more |
Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC. |
1Minv 1Electronic Identification Cards Client Jun 17, 2026 Jun 28, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to execute arbitrary code (.cgi, .pl, or .php) or delete arbitrary files...Show more |
1Medtronic 19Minimed 508 Firmware Minimed Paradigm 511 FirmwareMinimed Paradigm 512 Firmware+16 moreJun 17, 2026 Jun 28, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication pr...Show more |
1Kubevirt 1Containerized Data Importer Jun 17, 2026 Jun 28, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning feature does not determine whether the requesting user has permission to access the Persistent Volume C...Show more |
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. A...Show more |
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute val...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jun 27, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected device. The vulnerabili...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jun 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative...Show more |
In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin. |
1Oracle 9Communications Diameter Signaling Router Communications Network IntegrityHyperion Infrastructure Technology+6 moreJun 17, 2026 Jun 19, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerabi...Show more |
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuratio...Show more |
1Ishekar 1Endoscope Camera Firmware Nov 21, 2024 Jun 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera th...Show more |
OPNsense 18.7.x before 18.7.7 has Incorrect Access Control. |
1Bd 1Alaris Gateway Workstation Firmware Jun 17, 2026 Jun 13, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the...Show more |
1Siemens 2Simatic Mv420 Firmware Simatic Mv440 FirmwareJun 17, 2026 Jun 12, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). An authenticated attacker could escalate privileges by sending specially crafted requests to the integrated webserver. The security vul...Show more |
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without an...Show more |