CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2024-22234
HIGH
Spring Security <6.1.7 & <6.2.2 - Info Disclosure
CVSS 7.4
CVE-2024-25981
MEDIUM
moodle 4.1.0-4.1.8, 4.3.0-4.3.2 - Improper Access Control in Forum Export
CVSS 4.3
CVE-2024-25980
MEDIUM
moodle 4.1.0-4.1.8, 4.3.0-4.3.2 - Improper Access Control in H5P Attempts Report
CVSS 4.3
CVE-2024-1343
MEDIUM
LaborOfficeFree 19.10 - Authenticated Improper Access Control in Backup Directory
CVSS 4.7
CVE-2024-20951
MEDIUM
Oracle Customer Interaction History 12.2.3-12.2.13 - Unauthenticated Improper Access Control in Outcome-Result Component
CVSS 6.1
CVE-2024-20931
HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Unauthenticated Unauthorized Data Access via T3/IIOP
CVSS 7.5
CVE-2024-20929
MEDIUM
Oracle Application Object Library 12.2.3-12.2.13 - Unauthenticated Improper Access Control via DB Privileges
CVSS 6.5
CVE-2024-20927
HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Unauthenticated Improper Access Control via HTTP
CVSS 8.6
CVE-2024-20911
LOW
Oracle Audit Vault and Database Firewall 20.1-20.9 - Unauthorized Data Access via Firewall Component
CVSS 2.6
CVE-2024-0036
HIGH
Android - Local Privilege Escalation via ActivityTaskManagerService Logic Error
CVSS 7.8
CVE-2024-0032
MEDIUM
Android - Local Privilege Escalation via Improper Directory Access Control
CVSS 6.5
CVE-2024-24386
HIGH
VitalPBX 3.2.4-5 - Arbitrary Code Execution via Scripts Folder
CVSS 7.2
CVE-2024-24300
CRITICAL
4ipnet EAP-767 v3.42.00 - Improper Access Control via Static Session Cookie
CVSS 9.8
CVE-2024-25121
HIGH
TYPO3 8.0.0-8.7.56 - Authenticated Improper Access Control in File Abstraction Layer
CVSS 7.1
CVE-2024-25120
MEDIUM
TYPO3 Core - Unauthorized Resource Access via t3:// URI Scheme
CVSS 4.3
CVE-2024-24751
MEDIUM
sf_event_mgt 7.0.0-7.3.9 - Improper Access Control in Backend Module
CVSS 4.3
CVE-2024-21401
CRITICAL
Microsoft Entra Jira Single-Sign-On Plugin < 1.1.2 - Elevation of Privilege
CVSS 9.8
CVE-2024-21376
CRITICAL
Azure Kubernetes Service - Remote Code Execution in Confidential Container
CVSS 9.0
CVE-2024-21364
CRITICAL
Microsoft Azure Site Recovery - Elevation of Privilege
CVSS 9.3
CVE-2024-20695
MEDIUM
Skype for Business - Info Disclosure
CVSS 5.7
CVE-2024-1439
MEDIUM
Moodle < 4.2.11 - Improper Access Control
CVSS 6.5
CVE-2024-24776
LOW
Mattermost < 8.1.7 and 8.1.8 - Unauthenticated Channel Member Count Leak via API
CVSS 3.1
CVE-2024-25677
HIGH
Min < 1.31.0 - Improper Access Control via Local File Origin Handling
CVSS 8.8
CVE-2024-25106
CRITICAL
OpenObserve < 0.8.0 - Authenticated Unauthorized User Removal via /api/{org_id}/users/{email_id} Endpoint
CVSS 9.1
CVE-2024-24830
CRITICAL
OpenObserve < 0.8.0 - Authenticated Privilege Escalation via User Creation Endpoint
CVSS 9.9
Details
Vulnerabilities
5,300