CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,223 vulnerabilities with CWE-284
CVE-2026-58039
LOW
Node - Improper Access Control
CVSS 3.3
CVE-2026-62246
HIGH
Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation
CVSS 8.5
CVE-2026-66803
CRITICAL
Azure Cosmos DB Remote Code Execution Vulnerability
CVSS 10.0
CVE-2026-58043
HIGH
Node - Improper Access Control
CVSS 7.5
CVE-2026-15250
MEDIUM
LatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking Funnel
CVSS 5.3
CVE-2026-14222
LOW
Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization
CVSS 3.8
CVE-2026-14221
LOW
Easy Appointments <= 3.12.26 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization
CVSS 3.8
CVE-2026-11782
MEDIUM
Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Wallet and Points Tampering
CVSS 5.9
CVE-2026-18004
MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via Speech Policy Enforcement
CVSS 4.3
CVE-2026-17996
MEDIUM
Google Chrome < 151.0.7922.72 - Navigation Restriction Bypass via Malicious File on macOS
CVSS 6.2
CVE-2026-17994
MEDIUM
Google Chrome on Android < 151.0.7922.72 - Navigation Restriction Bypass via Media Implementation
CVSS 4.3
CVE-2026-17986
MEDIUM
Google Chrome < 151.0.7922.72 - Same Origin Policy Bypass via Bluetooth Policy Enforcement
CVSS 6.5
CVE-2026-17976
MEDIUM
Google Chrome < 151.0.7922.72 - Extension Policy Bypass via Crafted Domain Name
CVSS 4.3
CVE-2026-17961
MEDIUM
Google Chrome < 151.0.7922.72 - Navigation Restriction Bypass via Crafted HTML Page in Session Implementation
CVSS 4.3
CVE-2026-17944
MEDIUM
Google Chrome for iOS < 151.0.7922.72 - Security Restriction Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-17917
MEDIUM
Google Chrome for iOS < 151.0.7922.72 - Security Policy Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-17781
MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via Malicious Extension
CVSS 4.3
CVE-2026-67431
HIGH
MCP Ruby SDK: Ruby SSE Session Poisoning
CVE-2026-65888
CRITICAL
Joomla Gridbox < 2.20.2 - Account Takeover via socialLogin
CVE-2026-65887
CRITICAL
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2
CVE-2026-65889
CRITICAL
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2
CVE-2026-65943
HIGH
Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
CVSS 7.5
CVE-2026-65884
CRITICAL
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2
CVE-2026-41920
CRITICAL
Apache Traffic Server: SNI to Host header matching policy is not properly enforced
CVSS 9.3
CVE-2026-63236
LOW
Three Learning Koollab LMS 5.3.2 - Unauthenticated SCORM Data Exposure
CVSS 3.7
Details
Vulnerabilities
6,223