CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-31967 CRITICAL
Mitel <6.3.3 - Privilege Escalation
CVSS 9.1
CVE-2024-31964 HIGH
Mitel 6800/6900 Series SIP Phones <=6.3 SP3 HF4, 6900w <=6.3.3, 6970 <=5.1.1 SP8 - Auth Bypass & DoS
CVSS 7.5
CVE-2024-33393 MEDIUM
spidernet-io spiderpool <0.9.3 - RCE
CVSS 6.2
CVE-2024-22830 MEDIUM
Anti-Cheat Expert's Windows kernel module <1.0.2202.6217 - Privileg...
CVSS 5.3
CVE-2024-32973 MEDIUM
Pluto >= 0.9.0 < 0.9.3 - TLS Certificate Validation Bypass
CVSS 4.8
CVE-2024-28978 MEDIUM
Dell OpenManage Enterprise 3.10 and 4.0 - Improper Access Control
CVSS 5.2
CVE-2024-3746 MEDIUM
ScadaPro Server - Unauthenticated Arbitrary File Write via Default Directory Permissions
CVSS 5.5
CVE-2024-4225 HIGH
NetGuardian DIN RTU - Privilege Escalation, XSS, CSRF
CVSS 7.6
CVE-2024-33260 MEDIUM
Jerryscript - Denial of Service via Parser Class Parsing
CVSS 5.1
CVE-2024-4198 LOW
Mattermost 8.1.0-8.1.11 9.5.0-9.5.2 9.6.0 - Authenticated Role Demotion via Crafted HTTP Requests
CVSS 2.7
CVE-2024-4195 LOW
Mattermost 8.1.0-8.1.11 9.5.0-9.5.2 - Authenticated Role Escalation via Crafted HTTP Requests
CVSS 2.7
CVE-2024-33673 HIGH
Veritas Backup Exec < 23.0 - DLL Hijacking via Windows DLL Search Path
CVSS 7.8
CVE-2024-33666 HIGH
Zammad < 6.3.0 - Unauthorized Time Accounting Data Access via API
CVSS 8.6
CVE-2024-23271 MEDIUM
Safari < 17.3 - Improper Access Control
CVSS 6.5
CVE-2024-27348 CRITICAL KEV
Apache HugeGraph-Server - Remote Command Execution
CVSS 9.8
CVE-2024-22811 HIGH
Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 - DoS
CVSS 8.2
CVE-2024-22807 MEDIUM
PathPilot Controller 2.9.6 - Improper Access Control
CVSS 6.5
CVE-2024-32418 CRITICAL
flusity CMS 2.33 - Remote Code Execution via add_addon.php
CVSS 9.8
CVE-2024-31846 HIGH
Italtel Embrace <1.6.4 - Info Disclosure
CVSS 7.5
CVE-2024-30107 LOW
HCL Connections - Improper Access Control
CVSS 3.5
CVE-2024-31503 HIGH
Dolibarr ERP CRM < 19.0.1 - Authenticated Session Cookie and CSRF Token Theft via Crafted Web Page
CVSS 7.5
CVE-2024-31759 HIGH
PublicCMS <4.0.202302.e - Privilege Escalation
CVSS 8.8
CVE-2024-21115 HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2024-21114 HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Privilege Escalation in Core Component
CVSS 8.8
CVE-2024-21113 HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Privilege Escalation in Core Component
CVSS 8.8
Details
Vulnerabilities 5,300