CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-1308 HIGH
WooCommerce Cloak Affiliate Links <1.0.33 - Info Disclosure
CVSS 7.5
CVE-2024-0899 MEDIUM
s2Member < 230815 - Unauthenticated Information Exposure via API
CVSS 5.3
CVE-2024-0626 MEDIUM
WooCommerce Clover Payment Gateway <1.3.1 - Info Disclosure
CVSS 5.3
CVE-2024-29993 HIGH
Azure CycleCloud - Privilege Escalation
CVSS 8.8
CVE-2024-29990 CRITICAL
Microsoft Azure Kubernetes Service - Privilege Escalation
CVSS 9.0
CVE-2024-29055 HIGH
Microsoft Defender for IoT 22.0.0-24.1.2 - Elevation of Privilege
CVSS 7.2
CVE-2024-29054 HIGH
Microsoft Defender for IoT 22.0.0-24.1.2 - Elevation of Privilege
CVSS 7.2
CVE-2024-28922 MEDIUM
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2012-2022 - Secure Boot Security Feature Bypass
CVSS 4.1
CVE-2024-28917 MEDIUM
Azure Arc Extensions - Cluster-Scope Elevation of Privilege via Improper Access Control
CVSS 6.2
CVE-2024-26234 MEDIUM
Windows 10 1507-22H2, Windows 11 21H2-23H2, Windows Server 2008-2012 - Proxy Driver Spoofing
CVSS 6.7
CVE-2024-21424 MEDIUM
Azure Compute Gallery - Elevation of Privilege
CVSS 6.5
CVE-2024-31805 MEDIUM
TOTOLINK EX200 V4.0.3c.7646_B20201211 - Command Injection
CVSS 6.5
CVE-2024-27895 HIGH
HarmonyOS - Improper Access Control in Window Module
CVSS 7.5
CVE-2024-30418 HIGH
Huawei EMUI and HarmonyOS - Unauthenticated Denial of Service via App Management Module
CVSS 7.5
CVE-2024-2447 MEDIUM
Mattermost <8.1.11-9.5.2 - Privilege Escalation
CVSS 6.5
CVE-2024-29221 MEDIUM
Mattermost Server <9.5.2-8.1.11 - Info Disclosure
CVSS 4.7
CVE-2024-21848 LOW
Mattermost Server <8.1.11 - Privilege Escalation
CVSS 3.1
CVE-2024-31207 MEDIUM
NPM Vite < 2.9.18 - Information Disclosure
CVSS 5.9
CVE-2024-30261 LOW
Undici < 5.28.4 - Improper Access Control via Integrity Option Tampering
CVSS 2.6
CVE-2024-1418 MEDIUM
CGC Maintenance Mode <1.3 - Info Disclosure
CVSS 5.3
CVE-2024-3270 LOW
ThingsBoard < 3.6.2 - Improper Access Control in AdvancedFeature
CVSS 3.8
CVE-2024-20302 MEDIUM
Cisco Nexus Dashboard Orchestrator - Privilege Escalation
CVSS 5.4
CVE-2024-20283 MEDIUM
Cisco Nexus Dashboard - Info Disclosure
CVSS 4.3
CVE-2024-27605 HIGH
Alldata V0.4.6 - Improper Access Control
CVSS 7.5
CVE-2024-27602 CRITICAL
Alldata V0.4.6 - Improper Access Control
CVSS 9.1
Details
Vulnerabilities 5,300