CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2024-21112
HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2024-21110
HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Remote Code Execution via Core Component
CVSS 7.3
CVE-2024-21107
MEDIUM
Oracle VM VirtualBox < 7.0.16 - Authenticated Privilege Escalation in Core Component
CVSS 6.7
CVE-2024-21103
HIGH
Oracle VM VirtualBox < 7.0.16 - Authenticated Privilege Escalation
CVSS 7.8
CVE-2024-21091
MEDIUM
Oracle Agile Product Lifecycle Management for Process 6.2.4.2 - Unauthorized Data Access via Data Import
CVSS 6.5
CVE-2024-21084
MEDIUM
Oracle BI Publisher 7.0.0.0.0 and 12.2.1.4.0 - Unauthenticated Unauthorized Data Access via Service Gateway
CVSS 5.8
CVE-2024-21076
HIGH
Oracle Trade Management 12.2.3-12.2.13 - Unauthenticated Unauthorized Data Access via Offer LOV
CVSS 7.5
CVE-2024-21074
HIGH
Oracle Trade Management 12.2.3-12.2.13 - Unauthenticated Improper Access Control in Finance LOV
CVSS 7.5
CVE-2024-21071
CRITICAL
Oracle Workflow 12.2.3-12.2.13 - Authenticated Remote Code Execution via Admin Screens and Grants UI
CVSS 9.1
CVE-2024-21067
HIGH
Oracle Enterprise Manager Base Platform 13.5.0.0 - Authenticated Privilege Escalation in Host Management
CVSS 8.8
CVE-2024-20992
MEDIUM
Oracle WebCenter Portal 12.2.1.4.0 - Unauthorized Data Access via Content Integration
CVSS 4.4
CVE-2024-24487
MEDIUM
Silex Technology DS-600 <1.4.1 - DoS
CVSS 6.8
CVE-2024-24486
CRITICAL
Silex Technology DS-600 Firmware 1.4.1 - Unauthorized Device Settings Modification
CVSS 9.1
CVE-2024-24485
HIGH
Silex Technology DS-600 Firmware <1.4.1 - Info Disclosure
CVSS 7.5
CVE-2024-29843
HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29842
HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29841
HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29840
HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29839
HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 7.5
CVE-2024-29837
HIGH
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 8.8
CVE-2024-29836
CRITICAL
Evolution Controller <2.04.560.31.03.2024 - Info Disclosure
CVSS 9.8
CVE-2024-3765
CRITICAL
Sofia Service - Improper Access Controls
CVSS 9.8
CVE-2024-25852
HIGH
Linksys RE7000 - Command Injection
CVSS 8.8
CVE-2024-2217
HIGH
gaizhenbiao/chuanhuchatgpt - Info Disclosure
CVSS 7.5
CVE-2024-2731
MEDIUM
Mautic <= 4.4.9 - Information Disclosure
CVSS 5.4
Details
Vulnerabilities
5,300