CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2024-31967
CRITICAL
Mitel <6.3.3 - Privilege Escalation
CVSS 9.1
CVE-2024-31964
HIGH
Mitel 6800/6900 Series SIP Phones <=6.3 SP3 HF4, 6900w <=6.3.3, 6970 <=5.1.1 SP8 - Auth Bypass & DoS
CVSS 7.5
CVE-2024-33393
MEDIUM
spidernet-io spiderpool <0.9.3 - RCE
CVSS 6.2
CVE-2024-22830
MEDIUM
Anti-Cheat Expert's Windows kernel module <1.0.2202.6217 - Privileg...
CVSS 5.3
CVE-2024-32973
MEDIUM
Pluto >= 0.9.0 < 0.9.3 - TLS Certificate Validation Bypass
CVSS 4.8
CVE-2024-28978
MEDIUM
Dell OpenManage Enterprise 3.10 and 4.0 - Improper Access Control
CVSS 5.2
CVE-2024-3746
MEDIUM
ScadaPro Server - Unauthenticated Arbitrary File Write via Default Directory Permissions
CVSS 5.5
CVE-2024-4225
HIGH
NetGuardian DIN RTU - Privilege Escalation, XSS, CSRF
CVSS 7.6
CVE-2024-33260
MEDIUM
Jerryscript - Denial of Service via Parser Class Parsing
CVSS 5.1
CVE-2024-4198
LOW
Mattermost 8.1.0-8.1.11 9.5.0-9.5.2 9.6.0 - Authenticated Role Demotion via Crafted HTTP Requests
CVSS 2.7
CVE-2024-4195
LOW
Mattermost 8.1.0-8.1.11 9.5.0-9.5.2 - Authenticated Role Escalation via Crafted HTTP Requests
CVSS 2.7
CVE-2024-33673
HIGH
Veritas Backup Exec < 23.0 - DLL Hijacking via Windows DLL Search Path
CVSS 7.8
CVE-2024-33666
HIGH
Zammad < 6.3.0 - Unauthorized Time Accounting Data Access via API
CVSS 8.6
CVE-2024-23271
MEDIUM
Safari < 17.3 - Improper Access Control
CVSS 6.5
CVE-2024-27348
CRITICAL
KEV
Apache HugeGraph-Server - Remote Command Execution
CVSS 9.8
CVE-2024-22811
HIGH
Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 - DoS
CVSS 8.2
CVE-2024-22807
MEDIUM
PathPilot Controller 2.9.6 - Improper Access Control
CVSS 6.5
CVE-2024-32418
CRITICAL
flusity CMS 2.33 - Remote Code Execution via add_addon.php
CVSS 9.8
CVE-2024-31846
HIGH
Italtel Embrace <1.6.4 - Info Disclosure
CVSS 7.5
CVE-2024-30107
LOW
HCL Connections - Improper Access Control
CVSS 3.5
CVE-2024-31503
HIGH
Dolibarr ERP CRM < 19.0.1 - Authenticated Session Cookie and CSRF Token Theft via Crafted Web Page
CVSS 7.5
CVE-2024-31759
HIGH
PublicCMS <4.0.202302.e - Privilege Escalation
CVSS 8.8
CVE-2024-21115
HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2024-21114
HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Privilege Escalation in Core Component
CVSS 8.8
CVE-2024-21113
HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Privilege Escalation in Core Component
CVSS 8.8
Details
Vulnerabilities
5,300