CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2024-48905
CRITICAL
Sematell ReplyOne 7.4.3.0 - Improper Access Control in /rest/sessions Endpoint
CVSS 9.1
CVE-2024-30146
MEDIUM
HCL Domino Leap 1.1.3-1.1.4 - Improper Access Control in Application Import Endpoint
CVSS 4.1
CVE-2024-30148
MEDIUM
HCL Leap < 9.3.8 - Improper Access Control via Application Import Endpoint
CVSS 4.1
CVE-2024-53304
MEDIUM
LRQA Nettitude PoshC2 - Unauthenticated Remote Code Execution via Impersonation
CVSS 6.5
CVE-2024-54533
HIGH
macOS < 13.7.5, < 14.7.5, < 15.2 - Unprotected User Data Exposure via Permissions Issue
CVSS 7.0
CVE-2024-55963
MEDIUM
Appsmith RCE
CVSS 6.5
CVE-2024-53348
HIGH
loxilb < 0.9.7 - Improper Access Control
CVSS 7.4
CVE-2024-11045
CRITICAL
automatic1111/stable-diffusion-webui 1.10.0 - Cross-Site WebSocket Hijacking via Unvalidated WebSocket Connection
CVSS 9.6
CVE-2024-44313
HIGH
TastyIgniter < 4.0.0 - Unauthenticated Incorrect Access Control in Orders Invoice Function
CVSS 8.1
CVE-2024-54565
MEDIUM
macOS < 15.2 - Unprotected User Data Exposure
CVSS 6.2
CVE-2024-54559
MEDIUM
macOS < 15.2 - Unprotected User Data Exposure via Improper Access Control
CVSS 5.5
CVE-2024-13430
MEDIUM
Page Builder: Pagelayer < 1.9.8 - Authenticated Information Exposure via pagelayer_builder_posts_shortcode
CVSS 4.3
CVE-2024-9157
HIGH
Synaptics audio drivers - Privilege Escalation
CVSS 7.8
CVE-2024-13635
MEDIUM
VK Blocks <1.94.2.2 - Info Disclosure
CVSS 4.3
CVE-2024-56196
MEDIUM
Apache Traffic Server 10.0.0-10.0.3 - Improper Access Control
CVSS 6.3
CVE-2024-56195
MEDIUM
Apache Traffic Server 9.2.0-9.2.8 10.0.0-10.0.3 - Improper Access Control
CVSS 6.3
CVE-2024-51954
HIGH
ArcGIS Server <11.3 - Privilege Escalation
CVSS 8.5
CVE-2024-37567
CRITICAL
Infoblox NIOS 8.6.0-8.6.4 - Improper Access Control for Grids
CVSS 9.1
CVE-2024-37566
CRITICAL
Infoblox NIOS >=8.6.0 <8.6.4 - Improper Access Control
CVSS 9.8
CVE-2024-38291
HIGH
XIQ-SE <24.2.11 - Privilege Escalation
CVSS 8.8
CVE-2024-53573
CRITICAL
Unifiedtransform v2.X - Unauthenticated Improper Access Control via Teacher Edit Endpoint
CVSS 9.8
CVE-2024-36259
HIGH
Odoo Community/E 17.0 - Info Disclosure
CVSS 7.5
CVE-2024-12368
HIGH
Odoo 15.0 - Authenticated OAuth Token Export via auth_oauth Module
CVSS 8.1
CVE-2024-13693
MEDIUM
Enfold < 6.0.9 - Unauthenticated Sensitive Data Exposure via Missing Capability Check
CVSS 5.3
CVE-2024-53542
MEDIUM
NovaCHRON Smart Time Plus <8.6 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities
5,300