The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
79 vulnerabilities with CWE-1220
CVE-2025-4979
MEDIUM
GitLab CE/EE <17.10.7-18.0.1 - Info Disclosure
CVSS 4.9
CVE-2025-1110
LOW
Gitlab - Incorrect Authorization
CVSS 2.7
CVE-2025-32703
MEDIUM
Microsoft Visual Studio 2017 < 15.9.73 - Information Disclosure
CVSS 5.5
CVE-2025-1278
MEDIUM
GitLab CE/EE <17.9.8-17.11.2 - Auth Bypass
CVSS 5.3
CVE-2025-31201
CRITICAL
KEV
Apple Macos < 15.4.1 - Denial of Service
CVSS 9.8
CVE-2025-2408
MEDIUM
GitLab CE/EE <17.8.7-17.10.4 - Auth Bypass
CVSS 5.3
CVE-2025-29987
HIGH
Dell PowerProtect Data Domain <8.3.0.15 - Privilege Escalation
CVSS 8.8
CVE-2025-20111
HIGH
Cisco Nexus 3000/9000 - DoS
CVSS 7.4
CVE-2024-4147
MEDIUM
lunary-ai/lunary <1.2.13 - Privilege Escalation
CVSS 6.5
CVE-2024-21947
HIGH
System Management Mode - Memory Corruption
CVSS 7.5
CVE-2024-33058
HIGH
Memory Corruption - Buffer Overflow
CVSS 7.5
CVE-2024-12619
MEDIUM
GitLab CE/EE <17.8.6-17.10.1 - Privilege Escalation
CVSS 5.2
CVE-2024-6696
MEDIUM
Hitachi Vantara Pentaho <10.2.0.0-9.3.0.9 - Info Disclosure
CVSS 4.9
CVE-2024-39279
MEDIUM
Intel(R) Processors - DoS
CVSS 6.5
CVE-2024-21971
MEDIUM
AMD Crash Defender - DoS
CVSS 5.5
CVE-2024-53295
HIGH
Dell PowerProtect DD <8.3.0.0-7.13.1.20 - Privilege Escalation
CVSS 7.8
CVE-2024-11931
MEDIUM
GitLab CE/EE <17.6.4-17.7.3-17.8.1 - Info Disclosure
CVSS 6.4
CVE-2024-13272
MEDIUM
Drupal Paragraphs <2.0.2 - Info Disclosure
CVSS 6.3
CVE-2024-13256
HIGH
Drupal Email Contact <2.0.4 - Info Disclosure
CVSS 7.5
CVE-2024-52814
LOW
Argo Helm <0.45.0 - Privilege Escalation
CVSS 2.8
CVE-2024-52799
HIGH
Argo Workflows Chart <0.44.0 - RCE
CVSS 8.2
CVE-2024-43604
MEDIUM
Outlook for Android - Privilege Escalation
CVSS 5.7
CVE-2024-8927
HIGH
PHP <8.1.30, 8.2.*<8.2.24, 8.3.*<8.3.12 - Code Injection
CVSS 7.5
CVE-2024-6867
MEDIUM
lunary-ai/lunary <a761d833 - Info Disclosure
CVSS 6.5
CVE-2024-42365
HIGH
Asterisk < 18.24.2 - Remote Code Execution
CVSS 7.4
Details
Vulnerabilities
79