CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2024-21195 HIGH
Oracle BI Publisher 7.0.0.0.0, 7.6.0.0.0, 12.2.1.4.0 - Unauthorized Data Access and Partial DoS
CVSS 7.6
CVE-2024-45735 MEDIUM
Splunk Enterprise < 9.1.6 and 9.2.0-9.2.2 - Unauthorized App Key Value Store Access
CVSS 4.3
CVE-2024-45734 MEDIUM
Splunk 9.1.0-9.1.6 - Unauthorized File Read via PDF Export Dashboard Image Path
CVSS 4.3
CVE-2024-45397 MEDIUM
h2o HTTP Server - Spoofed Source Access Control Bypass
CVSS 5.9
CVE-2024-45149 LOW
Adobe Commerce <2.4.7-p2 - Privilege Escalation
CVSS 2.7
CVE-2024-45135 LOW
Adobe Commerce <2.4.7-p2 - Privilege Escalation
CVSS 2.7
CVE-2024-45133 LOW
Adobe Commerce <2.4.7-p2 - Info Disclosure
CVSS 2.7
CVE-2024-45130 MEDIUM
Adobe Commerce <2.4.7-p2 - Auth Bypass
CVSS 4.3
CVE-2024-45129 MEDIUM
Adobe Commerce <2.4.7-p2 - Privilege Escalation
CVSS 4.3
CVE-2024-45124 MEDIUM
Adobe Commerce <2.4.7-p2 - Auth Bypass
CVSS 5.3
CVE-2024-45122 MEDIUM
Adobe Commerce <2.4.7-p2 - Auth Bypass
CVSS 4.3
CVE-2024-45121 MEDIUM
Adobe Commerce <2.4.7-p2 - Privilege Escalation
CVSS 4.3
CVE-2024-45118 MEDIUM
Adobe Commerce <2.4.7-p2 - Privilege Escalation
CVSS 6.5
CVE-2024-42988 MEDIUM
CTFd 2.0.0-3.7.2 - Authenticated Improper Access Control in ChallengeSolves Endpoint
CVSS 4.3
CVE-2024-46539 HIGH
Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 - DoS
CVSS 8.2
CVE-2024-43590 HIGH
Visual Studio 2017, 2019, 2022 Elevation of Privilege via Visual C++ Redistributable Installer
CVSS 7.8
CVE-2024-43503 HIGH
Microsoft SharePoint Server - Improper Access Control
CVSS 7.8
CVE-2024-43456 MEDIUM
Windows Server 2008/2012/2016/2019/2022 Improper Access Control in Remote Desktop Services
CVSS 4.8
CVE-2024-47976 MEDIUM
Solidigm DC Products - Privilege Escalation
CVSS 6.7
CVE-2024-47975 HIGH
Solidigm DC Products - Info Disclosure
CVSS 7.0
CVE-2024-9576 HIGH
workbooth 2.5 - Privilege Escalation via Network Configuration Script
CVSS 7.0
CVE-2024-47910 HIGH
SonarSource SonarQube <9.9.5 LTA, <10.5 - Info Disclosure
CVSS 7.2
CVE-2024-45870 MEDIUM
BandiView 7.05 - Improper Access Control via Crafted POC File
CVSS 6.5
CVE-2024-42514 HIGH
Mitel MiContact Center Business <10.1.0.4 - Auth Bypass
CVSS 8.1
CVE-2024-45408 HIGH
elabftw 4.4.0-5.1.0 - Authenticated Improper Access Control
CVSS 7.5
Details
Vulnerabilities 5,300