CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2024-39934
HIGH
Robotmk <2.0.1 - Privilege Escalation
CVSS 7.8
CVE-2024-6428
MEDIUM
Mattermost <9.8.0 - Info Disclosure
CVSS 5.3
CVE-2024-39361
LOW
Mattermost 9.5.0-9.5.5, 9.6.0-9.6.2, 9.7.0-9.7.4, 9.8.0 - Improper Access Control via Post RemoteId Manipulation
CVSS 3.1
CVE-2024-36257
LOW
Mattermost <9.5.5, 9.8.0 - Info Disclosure
CVSS 2.7
CVE-2024-36989
HIGH
Splunk Enterprise <9.2.2, <9.1.5, <9.0.10 & Splunk Cloud <9.1.2312.200 - Bulletin Message Injection
CVSS 7.1
CVE-2024-38518
MEDIUM
BigBlueButton <2.6.17 - Auth Bypass
CVSS 4.6
CVE-2024-38371
HIGH
authentik < 2024.2.4 - Improper Access Control in OAuth2 Device Code Flow
CVSS 8.6
CVE-2024-37905
HIGH
authentik < 2024.2.4 - Improper Access Control via API-Access-Token Mechanism
CVSS 8.8
CVE-2024-39376
CRITICAL
marKoni D Compact and DH Exciter+Amplifiers Firmware < 2.0.1 - Improper Access Control
CVSS 9.8
CVE-2024-5655
CRITICAL
GitLab CE/EE <16.11.5-17.1.1 - Privilege Escalation
CVSS 9.6
CVE-2024-5430
MEDIUM
GitLab 16.10-16.11.4, 17.0-17.0.2, 17.1 - Improper Access Control via GraphQL
CVSS 6.8
CVE-2024-2191
MEDIUM
GitLab CE/EE <16.11.5-17.1.1 - Info Disclosure
CVSS 5.3
CVE-2024-37742
HIGH
Safe Exam Browser <3.5.0 - Info Disclosure
CVSS 8.2
CVE-2024-21741
CRITICAL
GigaDevice GD32E103C8T6 - Info Disclosure
CVSS 9.8
CVE-2024-21740
HIGH
Artery AT32F415CBT7-AT32F421C8T7 - Info Disclosure
CVSS 7.4
CVE-2024-33898
CRITICAL
Axiros AXESS Auto Configuration Server 4.x and 5.0.0 - Unauthenticated Remote Code Execution via Authorization Bypass
CVSS 9.8
CVE-2024-37677
HIGH
access_management_specialist V6.62.51215 - Improper Access Control
CVSS 7.5
CVE-2024-38873
MEDIUM
friendlycaptcha < 0.1.4 - Unauthenticated Captcha Bypass in ext:form Integration
CVSS 5.3
CVE-2024-38273
MEDIUM
Moodle 4.1.0-4.1.10 and 4.4.0-beta - Improper Access Control in BigBlueButton Join URL
CVSS 5.4
CVE-2024-5650
HIGH
Yokogawa Electric Corporation - CENTUM CAMS Log server - DLL Hijacking
CVSS 8.5
CVE-2024-37887
LOW
Nextcloud Server 27.0.0-27.1.9 - Improper Access Control in Shared Calendar Recurrence Exceptions
CVSS 3.5
CVE-2024-37884
LOW
Nextcloud Server 25.0.0-25.0.13.6 and 26.0.0-26.0.12 - Authenticated Improper Access Control via File Version Deletion
CVSS 3.5
CVE-2024-37883
MEDIUM
Nextcloud Deck 1.6.0-1.6.5 - Unauthorized Access to Deleted Card Comments and Attachments
CVSS 4.3
CVE-2024-37882
HIGH
Nextcloud Server 23.0.0-23.0.12.16 and 26.0.0-26.0.12 - Improper Access Control via Share Permission Escalation
CVSS 8.1
CVE-2024-37317
MEDIUM
Nextcloud Notes 4.6.0-4.9.2 - Improper Access Control via Shared Folder
CVSS 4.6
Details
Vulnerabilities
5,300