Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2024-08-14 CVE-2024-38163 Windows Update Stack Elevation of Privilege Vulnerability
local
low complexity
CWE-284
7.8
2024-08-12 CVE-2024-29082 Improper Access Control vulnerability in Vonets products
Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to bypass authentication and factory reset the device via unprotected goform endpoints.
network
low complexity
vonets CWE-284
8.6
2024-07-23 CVE-2024-38164 Improper Access Control vulnerability in Microsoft Groupme
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.
network
low complexity
microsoft CWE-284
8.8
2024-06-13 CVE-2024-34112 ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read.
network
low complexity
CWE-284
7.5
2024-06-13 CVE-2024-34107 Improper Access Control vulnerability in Adobe Commerce and Magento
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.
network
low complexity
adobe CWE-284
critical
9.8
2024-06-13 CVE-2024-26029 Improper Access Control vulnerability in Adobe Experience Manager
Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass.
network
low complexity
adobe CWE-284
critical
9.8
2024-06-06 CVE-2024-3404 Improper Access Control vulnerability in Gaizhenbiao Chuanhuchatgpt
In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms.
network
low complexity
gaizhenbiao CWE-284
6.5
2024-05-28 CVE-2024-22187 A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9.
network
low complexity
CWE-284
critical
9.1
2024-05-28 CVE-2024-23315 A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550E 1.2.10.9.
network
low complexity
CWE-284
7.5
2024-05-15 CVE-2024-34099 Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
CWE-284
7.8