Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2024-01-11 CVE-2024-0412 Improper Access Control vulnerability in Csdeshang Dsshop 3.0/3.1.0
A vulnerability was found in DeShang DSShop up to 3.1.0.
network
low complexity
csdeshang CWE-284
critical
9.8
2024-01-11 CVE-2024-0413 Improper Access Control vulnerability in Csdeshang Dskms 3.1.2
A vulnerability was found in DeShang DSKMS up to 3.1.2.
network
low complexity
csdeshang CWE-284
critical
9.8
2024-01-11 CVE-2024-0414 Improper Access Control vulnerability in Csdeshang Dscms 7.0/7.1
A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1.
network
low complexity
csdeshang CWE-284
critical
9.8
2024-01-11 CVE-2024-21666 Improper Access Control vulnerability in Pimcore Customer Management Framework
The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, personalization and marketing automation.
network
low complexity
pimcore CWE-284
6.5
2024-01-11 CVE-2024-21667 Improper Access Control vulnerability in Pimcore Customer Management Framework
pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore.
network
low complexity
pimcore CWE-284
6.5
2024-01-10 CVE-2023-46712 Improper Access Control vulnerability in Fortinet Fortiportal
A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to escalate its privilege via specifically crafted HTTP requests.
network
low complexity
fortinet CWE-284
8.8
2024-01-10 CVE-2024-0356 Improper Access Control vulnerability in Mandelo SSM Shiro Blog 1.0
A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic.
network
low complexity
mandelo CWE-284
7.5
2024-01-10 CVE-2024-0358 Improper Access Control vulnerability in Csdeshang Dso2O 4.1.0
A vulnerability was found in DeShang DSO2O up to 4.1.0.
network
low complexity
csdeshang CWE-284
7.5
2024-01-09 CVE-2023-7223 Improper Access Control vulnerability in Totolink T6 Firmware 4.1.9Cu.5241B20210923
A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923.
network
low complexity
totolink CWE-284
6.5
2023-12-22 CVE-2023-50928 Improper Access Control vulnerability in Amazon Awslabs Sandbox Accounts for Events
"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI.
network
low complexity
amazon CWE-284
critical
9.0