CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-3164 MEDIUM
dotcms - Improper Access Control in System Maintenance Portlet
CVSS 4.5
CVE-2024-28405 HIGH
SEMCMS 4.8 - Unauthenticated Incorrect Access Control via Early SEMCMS_Funtion.php Installation
CVSS 7.2
CVE-2024-28960 HIGH
Mbed TLS 2.18.0-2.28.x < 2.28.8 and 3.x < 3.6.0 and Mbed Crypto - Improper Access Control in PSA Crypto API
CVSS 8.2
CVE-2024-28016 MEDIUM
NEC Aterm Firmware - Unauthenticated Information Disclosure via Improper Access Control
CVSS 6.0
CVE-2024-25962 HIGH
Dell InsightIQ 5.0 - Unauthorized Access to Monitoring Data
CVSS 8.3
CVE-2024-25736 HIGH
WyreStorm Apollo VX20 Firmware < 1.3.58 - Unauthenticated Denial of Service via Reboot Endpoint
CVSS 7.5
CVE-2024-29866 CRITICAL
Datalust Seq <2023.4.11151, <2024.1.11146 - Privilege Escalation
CVSS 9.1
CVE-2024-25811 MEDIUM
Dreamer CMS 4.0.1 - Unauthenticated Sensitive Information Exposure via Backup File Download
CVSS 6.5
CVE-2024-1473 MEDIUM
Coming Soon & Maintenance Mode - Info Disclosure
CVSS 5.3
CVE-2024-1144 MEDIUM
Devklan's Alma Blog <2.1.10 - Info Disclosure
CVSS 6.5
CVE-2024-20767 HIGH KEV
CVE-2024-20767 - Adobe Coldfusion Arbitrary File Read
CVSS 7.4
CVE-2024-2481 MEDIUM
Surya2Developer Hostel Management System 1.0 - Info Disclosure
CVSS 6.5
CVE-2024-28390 CRITICAL
Advanced Plugins ultimateimagetool < 2.2.01 - Improper Access Control
CVSS 9.8
CVE-2024-25653 MEDIUM
Delinea Secret Server 11.4 - Broken Access Control in Report Functionality
CVSS 4.3
CVE-2024-20322 MEDIUM
Cisco IOS XR - Unauthenticated ACL Bypass via Pseudowire Interface
CVSS 5.8
CVE-2024-20319 MEDIUM
Cisco IOS XR - Unauthenticated Management Plane Protection Bypass via SNMP UDP Forwarding
CVSS 4.3
CVE-2024-20315 MEDIUM
Cisco IOS XR Software 7.9.1 7.9.2 7.10.1 - Unauthenticated ACL Bypass via MPLS Interface
CVSS 5.8
CVE-2024-1668 MEDIUM
Avada | Website Builder For WordPress & WooCommerce <7.11.5 - Info ...
CVSS 6.5
CVE-2024-1462 MEDIUM
Maintenance Page <1.0.8 - Info Disclosure
CVSS 5.3
CVE-2024-1370 MEDIUM
Maintenance Page <= 1.0.8 - Authenticated Unauthorized Data Access via subscribe_download AJAX Action
CVSS 5.3
CVE-2024-0687 MEDIUM
Restrict User Access - Info Disclosure
CVSS 5.3
CVE-2024-0631 MEDIUM
Duitku Payment Gateway <2.11.4 - Info Disclosure
CVSS 5.3
CVE-2024-0377 MEDIUM
LifterLMS < 7.5.1 - Unauthenticated Unrestricted Review Publication via Missing Capability Check
CVSS 5.3
CVE-2024-0369 MEDIUM
Bulk Edit Post Titles < 5.0.0 - Authenticated Arbitrary Post Title Modification via Missing Capability Check
CVSS 4.3
CVE-2024-28338 HIGH
TOTOLINK A8000RU V7.1cu.643_B20200521 - Unauthenticated Login Bypass via Session Cookie
CVSS 8.0
Details
Vulnerabilities 5,300