CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-21112 HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2024-21110 HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Remote Code Execution via Core Component
CVSS 7.3
CVE-2024-21107 MEDIUM
Oracle VM VirtualBox < 7.0.16 - Authenticated Privilege Escalation in Core Component
CVSS 6.7
CVE-2024-21103 HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Privilege Escalation
CVSS 7.8
CVE-2024-21091 MEDIUM
Oracle Agile Product Lifecycle Management for Process 6.2.4.2 - Unauthorized Data Access via Data Import
CVSS 6.5
CVE-2024-21084 MEDIUM
Oracle BI Publisher 7.0.0.0.0 and 12.2.1.4.0 - Unauthenticated Unauthorized Data Access via Service Gateway
CVSS 5.8
CVE-2024-21076 HIGH
Oracle Trade Management 12.2.3-12.2.13 - Unauthenticated Unauthorized Data Access via Offer LOV
CVSS 7.5
CVE-2024-21074 HIGH
Oracle Trade Management 12.2.3-12.2.13 - Unauthenticated Improper Access Control in Finance LOV
CVSS 7.5
CVE-2024-21071 CRITICAL
Oracle Workflow 12.2.3-12.2.13 - Authenticated Remote Code Execution via Admin Screens and Grants UI
CVSS 9.1
CVE-2024-21067 HIGH
Oracle Enterprise Manager Base Platform 13.5.0.0 - Authenticated Privilege Escalation in Host Management
CVSS 8.8
CVE-2024-20992 MEDIUM
Oracle WebCenter Portal 12.2.1.4.0 - Unauthorized Data Access via Content Integration
CVSS 4.4
CVE-2024-24487 MEDIUM
Silex Technology DS-600 <1.4.1 - DoS
CVSS 6.8
CVE-2024-24486 CRITICAL
Silex Technology DS-600 Firmware 1.4.1 - Unauthorized Device Settings Modification
CVSS 9.1
CVE-2024-24485 HIGH
Silex Technology DS-600 Firmware <1.4.1 - Info Disclosure
CVSS 7.5
CVE-2024-29843 HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29842 HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29841 HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29840 HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29839 HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29837 HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 8.8
CVE-2024-29836 CRITICAL
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 9.8
CVE-2024-3765 CRITICAL
Sofia Service - Improper Access Controls
CVSS 9.8
CVE-2024-25852 HIGH
Linksys RE7000 - Command Injection
CVSS 8.8
CVE-2024-2217 HIGH
gaizhenbiao/chuanhuchatgpt - Info Disclosure
CVSS 7.5
CVE-2024-2731 MEDIUM
Mautic <= 4.4.9 - Information Disclosure
CVSS 5.4
Details
Vulnerabilities 5,300