The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
100 vulnerabilities with CWE-1220
CVE-2025-29987
HIGH
Dell PowerProtect Data Domain <8.3.0.15 - Privilege Escalation
CVSS 8.8
CVE-2025-20111
HIGH
Cisco NX-OS Software - Unauthenticated Denial of Service via Crafted Ethernet Frames
CVSS 7.4
CVE-2024-21962
HIGH
AMD EPYC 4005 Series Processors - Privilege Escalation and Arbitrary Code Execution via AMD RAID Driver
CVE-2024-4147
MEDIUM
lunary-ai/lunary <1.2.13 - Privilege Escalation
CVSS 6.5
CVE-2024-21947
HIGH
System Management Mode - Memory Corruption
CVSS 7.5
CVE-2024-33058
HIGH
Memory Corruption - Buffer Overflow
CVSS 7.5
CVE-2024-12619
MEDIUM
GitLab CE/EE <17.8.6-17.10.1 - Privilege Escalation
CVSS 5.2
CVE-2024-6696
MEDIUM
Hitachi Vantara Pentaho <10.2.0.0-9.3.0.9 - Info Disclosure
CVSS 4.9
CVE-2024-39279
MEDIUM
Intel(R) processors - Authenticated Denial of Service via UEFI Firmware Access Control
CVSS 6.5
CVE-2024-21971
MEDIUM
AMD Ryzen 5000 and 7000 Series Desktop Processors - Denial of Service via AMD Crash Defender Input Validation
CVSS 5.5
CVE-2024-53295
HIGH
Dell PowerProtect DD <8.3.0.0-7.13.1.20 - Privilege Escalation
CVSS 7.8
CVE-2024-11931
MEDIUM
GitLab CE/EE <17.6.4-17.7.3-17.8.1 - Info Disclosure
CVSS 6.4
CVE-2024-13272
MEDIUM
Drupal Paragraphs <2.0.2 - Info Disclosure
CVSS 6.3
CVE-2024-13256
HIGH
Drupal Email Contact <2.0.4 - Info Disclosure
CVSS 7.5
CVE-2024-52814
LOW
Argo Helm <0.45.0 - Privilege Escalation
CVSS 2.8
CVE-2024-52799
HIGH
Argo Workflows Helm Chart <0.44.0 - Excessive Pod Exec Privileges
CVSS 8.2
CVE-2024-43604
MEDIUM
Outlook for Android - Privilege Escalation
CVSS 5.7
CVE-2024-8927
HIGH
PHP <8.1.30, 8.2.*<8.2.24, 8.3.*<8.3.12 - Code Injection
CVSS 7.5
CVE-2024-6867
MEDIUM
lunary-ai/lunary <a761d833 - Info Disclosure
CVSS 6.5
CVE-2024-42365
HIGH
Asterisk < 18.24.2 - Remote Code Execution
CVSS 7.4
CVE-2024-39324
LOW
ai-admin-graphql 2022.04.1-2022.10.9 - Insufficient Access Control via GraphQL API
CVSS 3.8
CVE-2024-39323
HIGH
ai-admin-graphql 2022.04.1-2022.10.9, 2023.04.1-2023.10.5, 2024.04.1-2024.04.5 - Improper Access Control
CVSS 7.1
CVE-2024-5389
HIGH
lunary < 1.4.9 - Insufficient Granularity of Access Control for Dataset Prompts
CVSS 8.1
CVE-2024-29200
MEDIUM
Kimai < 2.13.0 - Insufficient Access Control via API Timesheet Endpoint
CVSS 6.8
CVE-2024-26246
LOW
Microsoft Edge < 122.0.2365.92 - Security Feature Bypass
CVSS 3.9
Details
Vulnerabilities
100