CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-48905 CRITICAL
Sematell ReplyOne 7.4.3.0 - Improper Access Control in /rest/sessions Endpoint
CVSS 9.1
CVE-2024-30146 MEDIUM
HCL Domino Leap 1.1.3-1.1.4 - Improper Access Control in Application Import Endpoint
CVSS 4.1
CVE-2024-30148 MEDIUM
HCL Leap < 9.3.8 - Improper Access Control via Application Import Endpoint
CVSS 4.1
CVE-2024-53304 MEDIUM
LRQA Nettitude PoshC2 - Unauthenticated Remote Code Execution via Impersonation
CVSS 6.5
CVE-2024-54533 HIGH
macOS < 13.7.5, < 14.7.5, < 15.2 - Unprotected User Data Exposure via Permissions Issue
CVSS 7.0
CVE-2024-55963 MEDIUM
Appsmith RCE
CVSS 6.5
CVE-2024-53348 HIGH
loxilb < 0.9.7 - Improper Access Control
CVSS 7.4
CVE-2024-11045 CRITICAL
automatic1111/stable-diffusion-webui 1.10.0 - Cross-Site WebSocket Hijacking via Unvalidated WebSocket Connection
CVSS 9.6
CVE-2024-44313 HIGH
TastyIgniter < 4.0.0 - Unauthenticated Incorrect Access Control in Orders Invoice Function
CVSS 8.1
CVE-2024-54565 MEDIUM
macOS < 15.2 - Unprotected User Data Exposure
CVSS 6.2
CVE-2024-54559 MEDIUM
macOS < 15.2 - Unprotected User Data Exposure via Improper Access Control
CVSS 5.5
CVE-2024-13430 MEDIUM
Page Builder: Pagelayer < 1.9.8 - Authenticated Information Exposure via pagelayer_builder_posts_shortcode
CVSS 4.3
CVE-2024-9157 HIGH
Synaptics audio drivers - Privilege Escalation
CVSS 7.8
CVE-2024-13635 MEDIUM
VK Blocks <1.94.2.2 - Info Disclosure
CVSS 4.3
CVE-2024-56196 MEDIUM
Apache Traffic Server 10.0.0-10.0.3 - Improper Access Control
CVSS 6.3
CVE-2024-56195 MEDIUM
Apache Traffic Server 9.2.0-9.2.8 10.0.0-10.0.3 - Improper Access Control
CVSS 6.3
CVE-2024-51954 HIGH
ArcGIS Server <11.3 - Privilege Escalation
CVSS 8.5
CVE-2024-37567 CRITICAL
Infoblox NIOS 8.6.0-8.6.4 - Improper Access Control for Grids
CVSS 9.1
CVE-2024-37566 CRITICAL
Infoblox NIOS >=8.6.0 <8.6.4 - Improper Access Control
CVSS 9.8
CVE-2024-38291 HIGH
XIQ-SE <24.2.11 - Privilege Escalation
CVSS 8.8
CVE-2024-53573 CRITICAL
Unifiedtransform v2.X - Unauthenticated Improper Access Control via Teacher Edit Endpoint
CVSS 9.8
CVE-2024-36259 HIGH
Odoo Community/E 17.0 - Info Disclosure
CVSS 7.5
CVE-2024-12368 HIGH
Odoo 15.0 - Authenticated OAuth Token Export via auth_oauth Module
CVSS 8.1
CVE-2024-13693 MEDIUM
Enfold < 6.0.9 - Unauthenticated Sensitive Data Exposure via Missing Capability Check
CVSS 5.3
CVE-2024-53542 MEDIUM
NovaCHRON Smart Time Plus <8.6 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities 5,300