CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-37315 LOW
Nextcloud Server 23.0.0-23.0.11 and 26.0.0-26.0.11 - Authenticated Improper Access Control via File Version Restoration
CVSS 3.5
CVE-2024-37314 LOW
Nextcloud Server 25.0.0-25.0.7 - Improper Access Control in Photos App
CVSS 3.5
CVE-2024-37312 MEDIUM
nextcloud/user_oidc < 5.0.0 - Unauthenticated Account Registration via ID4me Endpoint
CVSS 6.3
CVE-2024-37279 MEDIUM
Kibana 8.6.3-8.13.0 - Authenticated Denial of Service via Alerting Rule Run Soon API
CVSS 4.3
CVE-2024-28969 MEDIUM
Dell Secure Connect Gateway 5.18.00.20-5.22.00.18 - Improper Access Control in Internal Update REST API
CVSS 4.3
CVE-2024-28968 MEDIUM
Dell Secure Connect Gateway 5.18.00.20-5.22.00.18 - Improper Access Control in REST APIs
CVSS 5.4
CVE-2024-28967 MEDIUM
Dell Secure Connect Gateway 5.18.00.20-5.22.00.18 - Improper Access Control in Internal Maintenance REST API
CVSS 5.4
CVE-2024-28966 MEDIUM
Dell Secure Connect Gateway 5.18.00.20-5.22.00.18 - Improper Access Control in Internal Update REST API
CVSS 5.4
CVE-2024-28965 MEDIUM
Dell Secure Connect Gateway 5.18.00.20-5.22.00.18 - Improper Access Control via Internal Enable REST API
CVSS 5.4
CVE-2024-34112 HIGH
ColdFusion <2023u7, 2021u13 - Info Disclosure
CVSS 7.5
CVE-2024-34107 MEDIUM
Adobe Commerce <2.4.7 - Privilege Escalation
CVSS 5.3
CVE-2024-26029 HIGH
Adobe Experience Manager < 6.5.21 and < 2024.5 - Security Feature Bypass via Improper Access Control
CVSS 7.5
CVE-2024-5840 MEDIUM
Google Chrome < 126.0.6478.54 - CORS Policy Bypass via Crafted HTML Page
CVSS 6.5
CVE-2024-29060 MEDIUM
Visual Studio 2017 15.0-15.9.62, 2019 16.0-16.11.36, 2022 17.4-17.4.19 - Elevation of Privilege
CVSS 6.7
CVE-2024-5687 MEDIUM
Firefox for Android - Info Disclosure
CVSS 5.3
CVE-2024-37289 HIGH
Trend Micro Apex One < 14.0.13139 and 14.0 < 14.0.0.12980 - Privilege Escalation
CVSS 7.8
CVE-2024-27855 HIGH
macOS Sonoma <14.5 - Info Disclosure
CVSS 8.8
CVE-2024-27819 LOW
iPadOS < 17.5 - Unauthenticated Contacts Access from Lock Screen
CVSS 2.4
CVE-2024-27792 MEDIUM
macOS Sonoma <14.4 - Info Disclosure
CVSS 5.5
CVE-2024-37568 HIGH
Authlib < 1.3.1 - Algorithm Confusion in JWT Verification
CVSS 7.5
CVE-2024-30481 MEDIUM
JCH Optimize < 4.0.0 - Broken Access Control
CVSS 6.5
CVE-2024-22074 CRITICAL
Dynamsoft Service - Incorrect Access Control
CVSS 9.8
CVE-2024-36399 HIGH
kanboard < 1.2.37 - Improper Access Control in ProjectPermissionController
CVSS 8.2
CVE-2024-0972 MEDIUM
BuddyPress Members Only <3.3.5 - Info Disclosure
CVSS 5.3
CVE-2024-28818 MEDIUM
Samsung Exynos 980 Firmware - Improper Access Control
CVSS 5.9
Details
Vulnerabilities 5,300