CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2024-0452
MEDIUM
WordPress AI ChatBot <5.3.4 - Info Disclosure
CVSS 5.0
CVE-2024-0451
MEDIUM
WordPress AI ChatBot <5.3.4 - Info Disclosure
CVSS 5.0
CVE-2024-4988
HIGH
TECNO com.transsion.videocallenhancer 1.1.9.973 - Unauthenticated Private File Leakage
CVSS 7.5
CVE-2024-36080
CRITICAL
Westermo EDW-100 through 2024-05-03 - Unauthenticated Hardcoded Root Credentials
CVSS 9.8
CVE-2024-21828
MEDIUM
Intel(R) Ethernet Controller <28.3 - Privilege Escalation
CVSS 6.7
CVE-2024-4263
MEDIUM
mlflow/mlflow <2.10.1 - Info Disclosure
CVSS 5.4
CVE-2024-28087
MEDIUM
Bonita Server < 10.1.0.W11 - Insecure Direct Object Reference via Missing Dynamic Permissions
CVSS 6.5
CVE-2024-34099
HIGH
Acrobat Reader <20.005.30574, 24.002.20736 - RCE
CVSS 7.8
CVE-2024-0437
MEDIUM
Password Protected - Ultimate Plugin <2.6.6 - Info Disclosure
CVSS 4.3
CVE-2024-30059
MEDIUM
Microsoft Intune - Privilege Escalation
CVSS 6.1
CVE-2024-33647
MEDIUM
Polarion ALM <V2404.0 - Info Disclosure
CVSS 6.5
CVE-2024-2749
MEDIUM
VikBooking Hotel Booking Engine & PMS < 1.6.8 - Improper Access Control
CVSS 5.9
CVE-2024-27841
MEDIUM
iOS <17.5- iPadOS <17.5 - macOS Sonoma <14.5 - Info Disclosure
CVSS 5.5
CVE-2024-27803
LOW
iPadOS < 17.5 - Unauthenticated Lock Screen Data Exposure via Shared Items
CVSS 2.4
CVE-2024-27790
HIGH
FileMaker Server <20.3.2 - Auth Bypass
CVSS 7.5
CVE-2024-1230
MEDIUM
SimpleShop <= 2.10.0 - Cross-Site Request Forgery via maybe_disconnect_simpleshop Function
CVSS 4.3
CVE-2024-0025
HIGH
Android - Local Privilege Escalation via ActivityManagerService Logic Error
CVSS 7.8
CVE-2024-29207
HIGH
UniFi Connect <3.7.9 - Info Disclosure
CVSS 7.5
CVE-2024-29206
LOW
UniFi Connect EV Station < 1.2.15 - Authenticated Improper Access Control via ADB Enablement
CVSS 2.2
CVE-2024-23351
HIGH
Qualcomm FastConnect and Flight RB5 5G Firmware - Memory Corruption via LPAC Submissions
CVSS 8.4
CVE-2024-34068
MEDIUM
Pterodactyl Panel <1.11.2 - Auth Bypass
CVSS 6.4
CVE-2024-34404
MEDIUM
Veritas NetBackup <10.4 - Privilege Escalation
CVSS 6.8
CVE-2024-33396
HIGH
karmada-io karmada v1.9.0 and before - Arbitrary Code Execution via Token Component
CVSS 8.4
CVE-2024-1678
MEDIUM
Subway Private Site Option <2.1.4 - Info Disclosure
CVSS 5.3
CVE-2024-1584
MEDIUM
Analytify < 5.2.1 - Unauthenticated Data Modification via wpa_check_authentication
CVSS 5.3
Details
Vulnerabilities
5,300