CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2024-45233
CRITICAL
Powermail extension <12.3.5 - Broken Access Control
CVSS 9.8
CVE-2024-44915
MEDIUM
IrfanView 4.67.1.0 - Denial of Service via Crafted EXR File
CVSS 5.5
CVE-2024-44914
MEDIUM
IrfanView 4.67.1.0 - Denial of Service via Crafted EXR File
CVSS 5.5
CVE-2024-44913
MEDIUM
Irfanview <4.67.1.0 - Memory Corruption
CVSS 5.5
CVE-2024-20279
MEDIUM
Cisco Application Policy Infrastructure Controller - Authenticated Improper Access Control in Restricted Security Domain
CVSS 4.3
CVE-2024-8216
MEDIUM
nafisulbari life_insurance_management_system 1.0 - Improper Access Control in Payment Handler
CVSS 5.4
CVE-2024-5814
MEDIUM
wolfssl < 5.7.0 - TLS Ciphersuite Downgrade via Incomplete Server Hello Parsing
CVSS 5.3
CVE-2024-36068
CRITICAL
Rubrik CDM <9.1.2-p1-8.1.3-p12 - RCE
CVSS 9.8
CVE-2024-8164
MEDIUM
beikeshop < 1.5.5 - Unrestricted File Upload via FileManagerController rename Function
CVSS 6.3
CVE-2024-43031
MEDIUM
autman 2.9.6 - Improper Access Control
CVSS 4.3
CVE-2024-42766
MEDIUM
Kashipara Bus Ticket Reservation System v1.0 - Info Disclosure
CVSS 5.4
CVE-2024-40766
CRITICAL
KEV
SonicWall - Improper Access Control
CVSS 9.8
CVE-2024-43477
HIGH
Microsoft Entra ID - Unauthenticated Improper Access Control in Decentralized Identity Services
CVSS 7.5
CVE-2024-42776
HIGH
Kashipara Hotel Management System v1.0 - Info Disclosure
CVSS 7.2
CVE-2024-42775
CRITICAL
Kashipara Hotel Management System <1.0 - Info Disclosure
CVSS 9.1
CVE-2024-42772
HIGH
Kashipara Hotel Management System <1.0 - Info Disclosure
CVSS 7.5
CVE-2024-43780
MEDIUM
Mattermost 9.5.0-9.5.7 9.8.0-9.8.2 9.9.0-9.9.1 9.10.0 - Unauthenticated File Upload via Guest User Channel Access
CVSS 4.3
CVE-2024-42497
MEDIUM
Mattermost <9.9.1-9.10.0 - Privilege Escalation
CVSS 6.0
CVE-2024-40884
LOW
Mattermost <9.5.8, <9.10.1 - Privilege Escalation
CVSS 2.7
CVE-2024-3127
MEDIUM
GitLab EE <17.1.6-17.2.4-17.3.1 - Auth Bypass
CVSS 4.3
CVE-2024-36441
MEDIUM
Swissphone DiCal-RED 4009 - Info Disclosure
CVSS 5.4
CVE-2024-36443
HIGH
Swissphone DiCal-RED 4009 - Info Disclosure
CVSS 7.6
CVE-2024-8071
MEDIUM
Mattermost <9.9.1-9.10.0 - Privilege Escalation
CVSS 4.7
CVE-2024-43813
MEDIUM
Mattermost 9.5.0-9.5.7 and 9.10.0 - Authenticated Improper Access Control
CVSS 4.3
CVE-2024-32939
MEDIUM
Mattermost 9.5.0-9.5.7 9.8.0-9.8.2 9.9.0-9.9.1 9.10.0 - Improper Access Control in Shared Channels
CVSS 4.3
Details
Vulnerabilities
5,300