CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-13855 MEDIUM
Prime Addons for Elementor <= 2.0.1 - Authenticated Insecure Direct Object Reference via pae_global_block Shortcode
CVSS 4.3
CVE-2024-13854 MEDIUM
Education Addon for Elementor <= 1.3.1 - IDOR via naedu_elementor_template Shortcode
CVSS 4.3
CVE-2024-56883 HIGH
Sage DPW <2024_12_001 - Incorrect Access Control
CVSS 8.1
CVE-2024-39327 CRITICAL
Atos Eviden IDRA <2.6.1 - Info Disclosure
CVSS 9.9
CVE-2024-57378 HIGH
Wazuh SIEM <4.8.2 - Privilege Escalation
CVSS 7.3
CVE-2024-13229 MEDIUM
Rank Math SEO - AI SEO Tools <1.0.235 - Info Disclosure
CVSS 4.3
CVE-2024-41934 MEDIUM
Intel(R) GPA software < 2024.3 - Authenticated Denial of Service via Local Access
CVSS 5.9
CVE-2024-39797 MEDIUM
Intel(R) Ethernet Connection I219 Series <12.19.1.39 - DoS
CVSS 6.5
CVE-2024-38310 HIGH
Intel(R) Graphics Driver - Privilege Escalation
CVSS 8.2
CVE-2024-37355 HIGH
Intel(R) Graphics - Privilege Escalation
CVSS 8.8
CVE-2024-36293 MEDIUM
Intel(R) Processors with Intel(R) SGX - Authenticated Denial of Service via EDECCSSA User Leaf Function
CVSS 6.5
CVE-2024-30211 MEDIUM
Intel(R) ME <2422.6.2.0 - Privilege Escalation
CVSS 6.0
CVE-2024-40586 MEDIUM
FortiClient <7.4.0 - Privilege Escalation
CVSS 6.7
CVE-2024-46432 HIGH
Tenda W18E V16.01.0.8(1625) - Unauthenticated Incorrect Access Control via setQuickCfgWifiAndLogin Function
CVSS 8.8
CVE-2024-46430 MEDIUM
Tenda W18E V16.01.0.8(1625) - Unauthenticated Password Change via setLoginPassword Function
CVSS 6.5
CVE-2024-57249 MEDIUM
Gleamtech FileVista 9.2.0.0 - Unauthenticated Unauthorized Access via Preview Function Header Removal
CVSS 6.5
CVE-2024-56889 HIGH
CodeAstro Complaint Mgt <1.0 - Privilege Escalation
CVSS 7.5
CVE-2024-13514 MEDIUM
B Slider- Gutenberg Slider Block <1.9.5 - Info Disclosure
CVSS 4.3
CVE-2024-35177 HIGH
Wazuh 3.0.0-4.8.0 - Local Privilege Escalation via Non-Default Installation Directory ACL
CVSS 7.8
CVE-2024-56898 HIGH
Geovision GV-ASWeb <6.1.0.0 - Privilege Escalation
CVSS 8.8
CVE-2024-57433 HIGH
macrozheng mall-tiny 1.0.1 - Improper Access Control via Logout Function
CVSS 7.5
CVE-2024-23920 HIGH
ChargePoint Home Flex Firmware - Unauthenticated Remote Code Execution via Onboardee Module
CVSS 8.8
CVE-2024-13457 MEDIUM
WordPress - Insecure Direct Object Reference
CVSS 5.3
CVE-2024-57360 MEDIUM
GNU Binutils >=2.43 - Local Info Disclosure
CVSS 5.5
CVE-2024-57032 CRITICAL
WeGIA < 3.2.0 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 5,300