CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-52509 LOW
Nextcloud Mail 2.2.0-2.2.9 - Improper Access Control via Shared File Attachment
CVSS 3.5
CVE-2024-50653 HIGH
crmeb <= 5.4.0 - Incorrect Access Control via Coupon Collection Packet Replay
CVSS 7.5
CVE-2024-20373 MEDIUM
Cisco IOS XE SD-WAN - Unauthenticated SNMP Access Control Bypass via IPv4 ACL Misconfiguration
CVSS 5.3
CVE-2024-11214 MEDIUM
Best Employee Management System 1.0 - Unrestricted File Upload via Profile Image Parameter
CVSS 4.7
CVE-2024-11211 MEDIUM
EyouCMS < 1.6.7 - Unrestricted File Upload in Website Logo Handler
CVSS 4.7
CVE-2024-39609 HIGH
Intel Server Board M70KLP2SB Firmware < 01.04.0030 - Privilege Escalation via Improper Access Control
CVSS 7.5
CVE-2024-39285 MEDIUM
Intel(R) Server M20NTP - Info Disclosure
CVSS 5.3
CVE-2024-36488 HIGH
Intel(R) DSA <24.3.26.8 - Privilege Escalation
CVSS 7.3
CVE-2024-34022 MEDIUM
Thunderbolt(TM) Share <1.0.49.9 - Privilege Escalation
CVSS 6.7
CVE-2024-32483 HIGH
Intel(R) EMA <1.13.1.0 - Privilege Escalation
CVSS 8.2
CVE-2024-32044 MEDIUM
Intel(R) Arc(TM) Pro Graphics <31.0.101.5319 - Privilege Escalation
CVSS 6.8
CVE-2024-29085 MEDIUM
BigDL <2.5.0 - Privilege Escalation
CVSS 5.5
CVE-2024-29077 MEDIUM
JAM STAPL Player <2.6.1 - Privilege Escalation
CVSS 6.7
CVE-2024-27200 MEDIUM
Intel Granulate <4.30.1 - Privilege Escalation
CVSS 4.4
CVE-2024-49049 HIGH
Visual Studio Code Remote Extension < 0.115.1 - Elevation of Privilege
CVSS 7.1
CVE-2024-49044 MEDIUM
Visual Studio 2022 17.6.0-17.6.21 - Elevation of Privilege
CVSS 6.7
CVE-2024-43530 HIGH
Windows 10/11 & Server 2022 Elevation of Privilege via Windows Update Stack
CVSS 7.8
CVE-2024-11138 LOW
DedeCMS 5.7.116 - Unrestricted File Upload via logoimg Parameter
CVSS 2.7
CVE-2024-2315 HIGH
AMI APTIO V 5.0-5.037 - Improper Access Control
CVSS 7.1
CVE-2024-50558 MEDIUM
Siemens SCALANCE and RUGGEDCOM Firmware < 8.2 - Improper Access Control
CVSS 4.3
CVE-2024-11122 MEDIUM
Lingdang CRM < 8.6.4.3 - Unrestricted File Upload via /crm/wechatSession/index.php
CVSS 6.3
CVE-2024-11054 MEDIUM
Simple Music Cloud Community System 1.0 - Unauthenticated Unrestricted File Upload via pp Argument
CVSS 6.3
CVE-2024-46948 MEDIUM
Northern.tech Mender < 3.6.5 and 3.7.x < 3.7.5 - Improper Access Control
CVSS 4.3
CVE-2024-11000 MEDIUM
CodeAstro Real Estate Management System 1.0 - Unrestricted File Upload via About Us Page aimage Parameter
CVSS 4.7
CVE-2024-10999 MEDIUM
CodeAstro Real Estate Management System 1.0 - Unrestricted File Upload via About Us Page aimage Parameter
CVSS 4.7
Details
Vulnerabilities 5,300