CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-22234 HIGH
Spring Security <6.1.7 & <6.2.2 - Info Disclosure
CVSS 7.4
CVE-2024-25981 MEDIUM
moodle 4.1.0-4.1.8, 4.3.0-4.3.2 - Improper Access Control in Forum Export
CVSS 4.3
CVE-2024-25980 MEDIUM
moodle 4.1.0-4.1.8, 4.3.0-4.3.2 - Improper Access Control in H5P Attempts Report
CVSS 4.3
CVE-2024-1343 MEDIUM
LaborOfficeFree 19.10 - Authenticated Improper Access Control in Backup Directory
CVSS 4.7
CVE-2024-20951 MEDIUM
Oracle Customer Interaction History 12.2.3-12.2.13 - Unauthenticated Improper Access Control in Outcome-Result Component
CVSS 6.1
CVE-2024-20931 HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Unauthenticated Unauthorized Data Access via T3/IIOP
CVSS 7.5
CVE-2024-20929 MEDIUM
Oracle Application Object Library 12.2.3-12.2.13 - Unauthenticated Improper Access Control via DB Privileges
CVSS 6.5
CVE-2024-20927 HIGH
Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 - Unauthenticated Improper Access Control via HTTP
CVSS 8.6
CVE-2024-20911 LOW
Oracle Audit Vault and Database Firewall 20.1-20.9 - Unauthorized Data Access via Firewall Component
CVSS 2.6
CVE-2024-0036 HIGH
Android - Local Privilege Escalation via ActivityTaskManagerService Logic Error
CVSS 7.8
CVE-2024-0032 MEDIUM
Android - Local Privilege Escalation via Improper Directory Access Control
CVSS 6.5
CVE-2024-24386 HIGH
VitalPBX 3.2.4-5 - Arbitrary Code Execution via Scripts Folder
CVSS 7.2
CVE-2024-24300 CRITICAL
4ipnet EAP-767 v3.42.00 - Improper Access Control via Static Session Cookie
CVSS 9.8
CVE-2024-25121 HIGH
TYPO3 8.0.0-8.7.56 - Authenticated Improper Access Control in File Abstraction Layer
CVSS 7.1
CVE-2024-25120 MEDIUM
TYPO3 Core - Unauthorized Resource Access via t3:// URI Scheme
CVSS 4.3
CVE-2024-24751 MEDIUM
sf_event_mgt 7.0.0-7.3.9 - Improper Access Control in Backend Module
CVSS 4.3
CVE-2024-21401 CRITICAL
Microsoft Entra Jira Single-Sign-On Plugin < 1.1.2 - Elevation of Privilege
CVSS 9.8
CVE-2024-21376 CRITICAL
Azure Kubernetes Service - Remote Code Execution in Confidential Container
CVSS 9.0
CVE-2024-21364 CRITICAL
Microsoft Azure Site Recovery - Elevation of Privilege
CVSS 9.3
CVE-2024-20695 MEDIUM
Skype for Business - Info Disclosure
CVSS 5.7
CVE-2024-1439 MEDIUM
Moodle < 4.2.11 - Improper Access Control
CVSS 6.5
CVE-2024-24776 LOW
Mattermost < 8.1.7 and 8.1.8 - Unauthenticated Channel Member Count Leak via API
CVSS 3.1
CVE-2024-25677 HIGH
Min < 1.31.0 - Improper Access Control via Local File Origin Handling
CVSS 8.8
CVE-2024-25106 CRITICAL
OpenObserve < 0.8.0 - Authenticated Unauthorized User Removal via /api/{org_id}/users/{email_id} Endpoint
CVSS 9.1
CVE-2024-24830 CRITICAL
OpenObserve < 0.8.0 - Authenticated Privilege Escalation via User Creation Endpoint
CVSS 9.9
Details
Vulnerabilities 5,300