CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-33027 HIGH
Qualcomm 315 5G IoT Modem Firmware - Memory Corruption via GPU Page Table Manipulation
CVSS 8.4
CVE-2024-41518 HIGH
Feripro <= 2.2.3 - Unauthenticated Information Disclosure via Admin Statistics Export
CVSS 7.5
CVE-2024-41926 LOW
Mattermost 9.5.0-9.5.6 and 9.9.0 - Improper Access Control via RemoteId Spoofing
CVSS 2.7
CVE-2024-41162 MEDIUM
Mattermost 9.5.0-9.5.6 9.7.0-9.7.5 9.8.0-9.8.1 9.9.0 - Unauthenticated Channel Modification via Shared Channels
CVSS 4.1
CVE-2024-41144 MEDIUM
Mattermost Server < 9.5.7 - Improper Access Control
CVSS 5.5
CVE-2024-39839 MEDIUM
Mattermost 9.5.0-9.5.6, 9.7.0-9.7.5, 9.8.0-9.8.1, 9.9.0 - Improper Access Control in Shared Channels
CVSS 4.3
CVE-2024-39837 LOW
Mattermost 9.5.0-9.5.6 and 9.9.0 - Unauthenticated Arbitrary Channel Creation via Shared Channels
CVSS 3.8
CVE-2024-39777 HIGH
Mattermost 9.5.0-9.5.6 9.7.0-9.7.5 9.8.0-9.8.1 9.9.0 - Improper Access Control via Shared Channel Invite
CVSS 8.7
CVE-2024-39274 HIGH
Mattermost 9.5.0-9.5.6 9.7.0-9.7.5 9.8.0-9.8.1 9.9.0 - Improper Access Control in Shared Channel Validation
CVSS 8.7
CVE-2024-36492 HIGH
Mattermost <9.9.0-9.8.1 - Privilege Escalation
CVSS 7.4
CVE-2024-29977 LOW
Mattermost 9.5.0-9.5.6 and 9.9.0 - Improper Access Control for Synced Reactions
CVSS 2.7
CVE-2024-5331 MEDIUM
Breakdance <1.7.2 - Info Disclosure
CVSS 4.3
CVE-2024-38909 CRITICAL
Studio 42 elFinder 2.1.64 - Improper Access Control via File Copy
CVSS 9.8
CVE-2024-40822 LOW
iPadOS < 16.7.9 and 17.6 - Unauthenticated Contacts Access from Lock Screen
CVSS 2.4
CVE-2024-40812 HIGH
iPadOS < 16.7.9 - Improper Access Control via Shortcut Internet Permission Bypass
CVSS 7.8
CVE-2024-40786 HIGH
iPadOS < 16.7.9 - Unauthorized Sensitive Information Exposure
CVSS 7.5
CVE-2024-28805 CRITICAL
Italtel i-MCS NFV 12.1.0-20211215 - Improper Access Control
CVSS 9.1
CVE-2024-6727 MEDIUM
Delphix Data Control Tower (DCT) < 19.0.0 - Broken Authentication via Enable-Scale-Testing Functionality
CVSS 5.4
CVE-2024-7154 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in Password Reset Handler
CVSS 4.3
CVE-2024-40117 CRITICAL
Solar-Log <v2.8.2 - Privilege Escalation
CVSS 9.8
CVE-2024-41806 MEDIUM
Open edX Platform - Info Disclosure
CVSS 5.3
CVE-2024-7057 MEDIUM
GitLab 16.7-17.0.4, 17.1-17.1.2, 17.2 - Information Disclosure via Job Artifacts
CVSS 4.3
CVE-2024-36535 CRITICAL
meshery <0.7.51 - Privilege Escalation
CVSS 9.8
CVE-2024-36537 HIGH
cert-manager <1.14.4 - Privilege Escalation
CVSS 7.2
CVE-2024-38164 CRITICAL
GroupMe - Unauthenticated Privilege Escalation via Malicious Link
CVSS 9.6
Details
Vulnerabilities 5,300