CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2024-47760
HIGH
GLPI <10.0.17 - Privilege Escalation
CVSS 8.8
CVE-2024-47758
HIGH
GLPI <10.0.17 - Privilege Escalation
CVSS 8.8
CVE-2024-12294
MEDIUM
WPBeginner plugin - Info Disclosure
CVSS 5.3
CVE-2024-43717
MEDIUM
Adobe Experience Manager < 6.5.22.0 and < 2024.11.0 - Security Feature Bypass via Improper Access Control
CVSS 4.3
CVE-2024-43716
MEDIUM
Adobe Experience Manager <6.5.22.0 and <2024.11.0 - Security Feature Bypass via Improper Access Control
CVSS 4.3
CVE-2024-54038
MEDIUM
Adobe Connect <12.6, 11.4.7 - Auth Bypass
CVSS 4.3
CVE-2024-11868
MEDIUM
LearnPress - WordPress LMS Plugin <4.2.7.3 - Info Disclosure
CVSS 5.3
CVE-2024-49600
HIGH
Dell Power Manager <3.17 - Privilege Escalation
CVSS 7.8
CVE-2024-12307
MEDIUM
Unifiedtransform <2.0 - Privilege Escalation
CVSS 4.3
CVE-2024-12306
MEDIUM
Unifiedtransform 2.0 - Info Disclosure
CVSS 4.3
CVE-2024-12235
MEDIUM
AgileBPM <= 1.0.0 - Improper Access Control in AuthorizationTokenCheckFilter
CVSS 6.3
CVE-2024-12233
HIGH
Online Notice Board <= 1.0 - Unrestricted File Upload via Profile Picture Handler
CVSS 7.3
CVE-2024-10937
MEDIUM
Related Posts plugin <2.0.58 - Info Disclosure
CVSS 5.3
CVE-2024-20397
MEDIUM
Cisco NX-OS Software - Privilege Escalation
CVSS 5.2
CVE-2024-11961
MEDIUM
Guangzhou Huayi Intelligent Technology Jeewms 3.7 - Info Disclosure
CVSS 5.3
CVE-2024-11674
MEDIUM
CodeAstro Hospital Management System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2024-11661
MEDIUM
Free Exam Hall Seating Management System 1.0 - Unrestricted File Upload in Profile Image Handler
CVSS 4.3
CVE-2024-11483
MEDIUM
Ansible Automation Platform - Privilege Escalation
CVSS 5.0
CVE-2024-8805
HIGH
BlueZ HID over GATT Profile - Access Control Code Execution
CVSS 8.8
CVE-2024-10393
MEDIUM
Tutor LMS < 2.7.6 - Unauthenticated User Registration Bypass via Missing users_can_register Check
CVSS 5.3
CVE-2024-11484
MEDIUM
Code4Berry Decoration Management System 1.0 - Improper Access Controls
CVSS 6.3
CVE-2024-48899
MEDIUM
Moodle 4.4.0-4.4.3 - Improper Access Control in Course Badge Listing
CVSS 4.3
CVE-2024-37155
MEDIUM
OpenCTI < 6.1.9 - Unauthenticated Improper Access Control via GraphQL Introspection Query Bypass
CVSS 6.5
CVE-2024-22067
MEDIUM
ZTE NH8091 Firmware - Authenticated Remote Code Execution via Web Module Interface
CVSS 6.8
CVE-2024-52514
MEDIUM
Nextcloud Server 21.0.0-21.0.9.18 27.0.0-27.1.9 - Improper Access Control via Folder Copy Bypass
CVSS 4.1
Details
Vulnerabilities
5,300