Fallos del tipo CWE-284

4356 resultados
CVE-2025-30433CRITICALThis issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15EPSS 1.1%CVE-2023-4546LOWByzoro Smart S85F Management Platform licence.php access controlEPSS 1.1%CVE-2022-46025CRITICALTotolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers to obtain Wi-Fi systEPSS 1.1%CVE-2024-34107MEDIUMAdobe Commerce | Improper Access Control (CWE-284)EPSS 1.1%CVE-2024-7919MEDIUMAnhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 GetDataList access controlEPSS 1.1%CVE-2026-21666CRITICALA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.EPSS 1.1%CVE-2026-21667CRITICALA vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.EPSS 1.1%CVE-2018-16838MEDIUMA flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings oEPSS 1.1%CVE-2019-11899HIGHAn unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. WEPSS 1.1%CVE-2017-18101Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.EPSS 1.1%CVE-2025-1595MEDIUMAnhui Xufan Information Technology EasyCVR getbaseconfig information disclosureEPSS 1.1%CVE-2022-1025All unpatched versions of Argo CD starting with v1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentEPSS 1.1%CVE-2021-24238Realteo < 1.2.4 - Arbitrary Property Deletion via IDOREPSS 1.1%CVE-2022-39337HIGHPermission bypass due to incorrect configuration in github.com/dromara/hertzbeatEPSS 1.1%CVE-2021-24359The Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email SendingEPSS 1.1%CVE-2019-15255MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 1.1%CVE-2018-19945Improper Limitation of a Pathname to a Restricted Directory in QTSEPSS 1.1%CVE-2020-3448MEDIUMCisco Cyber Vision Center Software Access Control Bypass VulnerabilityEPSS 1.1%CVE-2025-3668MEDIUMTOTOLINK A3700R cstecgi.cgi setScheduleCfg access controlEPSS 1.1%CVE-2024-11868MEDIUMLearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST APIEPSS 1.1%