CWE-284
7,733 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messa...Show more |
MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging knowledge of a CAPTCHA answer for a publ...Show more |
The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrati...Show more |
Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-5342. |
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative ac...Show more |
The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecified vectors. |
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a...Show more |
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation. |
Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitiv...Show more |
2Elastic Elasticsearch2Elasticsearch ElasticsearchApr 22, 2026 Jul 28, 2014 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only vio...Show more |
Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors. |
The ASUS WL-330NUL router has a configuration process that relies on accessing the 192.168.1.1 IP address, but the documentation advises users to instead access a DNS hostname that does not always resolve to 192.168.1.1,...Show more |
2Apache Oracle4Flexcube Private Banking Mysql Enterprise MonitorStruts+1 moreApr 29, 2026 Sep 30, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors. |
4Canonical DebianHaproxy+1 more4Debian Linux Enterprise Linux Load BalancerHaproxy+1 moreApr 29, 2026 Aug 19, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index us...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Aug 16, 2013 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client. |
3Canonical OpensuseOracle3Jre OpensuseUbuntu LinuxApr 22, 2026 Apr 17, 2013 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOT...Show more |
1Rockwellautomation 12Compactlogix Controllers Firmware Compactlogix FirmwareControllogix Controllers Firmware+9 moreJun 3, 2026 Jan 24, 2013 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. Thi...Show more |
1Rockwellautomation 171756 Enbt 1756 Eweb1768 Enbt+14 moreApr 29, 2026 Jan 24, 2013 N/A· v4 N/A· v3 8.5 HIGH· v2 When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that changes the product’s configuration and network...Show more |
1Rockwellautomation 171756 Enbt 1756 Eweb1768 Enbt+14 moreJun 3, 2026 Jan 24, 2013 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter...Show more |
13s Software 1Codesys Runtime System Apr 29, 2026 Jan 21, 2013 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer file...Show more |