CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

4,788 vulnerabilities with CWE-284
CVE-2026-32254 HIGH
Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS
CVSS 7.1
CVE-2026-21994 CRITICAL
Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit 0.3.0 - RCE
CVSS 9.8
CVE-2026-30707 HIGH
SpeedExam Online Examination System FEV2026 - Auth Bypass
CVSS 8.1
CVE-2026-4221 HIGH
Tiandy Easy7 Integrated Management Platform Endpoint uploadLedImage unrestricted upload
CVSS 7.3
CVE-2026-4220 HIGH
Technologies Integrated Management Platform SetWebpagePic.jsp unrestricted upload
CVSS 7.3
CVE-2026-4218 LOW
myAEDES App aedes.me.beta EngageBayUtils.java information disclosure
CVSS 2.5
CVE-2026-4201 HIGH
glowxq glowxq-oj SysFileController.java upload unrestricted upload
CVSS 7.3
CVE-2026-4194 HIGH
D-Link DNS-1550-04 system_mgr.cgi cgi_set_wto access control
CVSS 7.3
CVE-2026-4193 HIGH
D-Link DIR-823G goahead UpdateClientInfo access control
CVSS 7.3
CVE-2026-4191 HIGH
node-api-postgres up to 2.5 - Unrestricted Upload
CVSS 7.3
CVE-2026-4180 HIGH
D-Link DIR-816 1.10CNB05 - Auth Bypass
CVSS 7.3
CVE-2026-3111 MEDIUM
Multiple vulnerabilities on the Educativa Campus
CVE-2026-3110 HIGH
Multiple vulnerabilities on the Educativa Campus
CVE-2026-32720 HIGH
Improper Access Control in github.com/ctfer-io/monitoring
CVE-2026-0977 MEDIUM
IBM CICS Transaction Gateway 9.3-10.1 - Path Traversal
CVSS 5.1
CVE-2026-4105 MEDIUM
systemd - Privilege Escalation
CVSS 6.7
CVE-2026-32138 HIGH
NEXULEAN <2.0.0 - Info Disclosure
CVSS 8.2
CVE-2026-21667 CRITICAL
Backup Server - Authenticated RCE
CVSS 9.9
CVE-2026-21666 CRITICAL
Backup Server - Authenticated RCE
CVSS 9.9
CVE-2026-3940 MEDIUM
Google Chrome <146.0.7680.71 - Auth Bypass
CVSS 5.3
CVE-2026-3939 MEDIUM
Google Chrome <146.0.7680.71 - Auth Bypass
CVSS 5.3
CVE-2026-3938 MEDIUM
Google Chrome <146.0.7680.71 - Info Disclosure
CVSS 4.3
CVE-2026-3934 MEDIUM
Google Chrome <146.0.7680.71 - Auth Bypass
CVSS 6.5
CVE-2026-3932 HIGH
Google Chrome Android <146.0.7680.71 - Auth Bypass
CVSS 7.5
CVE-2026-27591 CRITICAL
Winter CMS <1.0.477/1.1.12/1.2.12 - Privilege Escalation
CVSS 9.9
Details
Vulnerabilities 4,788