CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
4,788 vulnerabilities with CWE-284
CVE-2026-32254
HIGH
Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS
CVSS 7.1
CVE-2026-21994
CRITICAL
Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit 0.3.0 - RCE
CVSS 9.8
CVE-2026-30707
HIGH
SpeedExam Online Examination System FEV2026 - Auth Bypass
CVSS 8.1
CVE-2026-4221
HIGH
Tiandy Easy7 Integrated Management Platform Endpoint uploadLedImage unrestricted upload
CVSS 7.3
CVE-2026-4220
HIGH
Technologies Integrated Management Platform SetWebpagePic.jsp unrestricted upload
CVSS 7.3
CVE-2026-4218
LOW
myAEDES App aedes.me.beta EngageBayUtils.java information disclosure
CVSS 2.5
CVE-2026-4201
HIGH
glowxq glowxq-oj SysFileController.java upload unrestricted upload
CVSS 7.3
CVE-2026-4194
HIGH
D-Link DNS-1550-04 system_mgr.cgi cgi_set_wto access control
CVSS 7.3
CVE-2026-4193
HIGH
D-Link DIR-823G goahead UpdateClientInfo access control
CVSS 7.3
CVE-2026-4191
HIGH
node-api-postgres up to 2.5 - Unrestricted Upload
CVSS 7.3
CVE-2026-4180
HIGH
D-Link DIR-816 1.10CNB05 - Auth Bypass
CVSS 7.3
CVE-2026-3111
MEDIUM
Multiple vulnerabilities on the Educativa Campus
CVE-2026-3110
HIGH
Multiple vulnerabilities on the Educativa Campus
CVE-2026-32720
HIGH
Improper Access Control in github.com/ctfer-io/monitoring
CVE-2026-0977
MEDIUM
IBM CICS Transaction Gateway 9.3-10.1 - Path Traversal
CVSS 5.1
CVE-2026-4105
MEDIUM
systemd - Privilege Escalation
CVSS 6.7
CVE-2026-32138
HIGH
NEXULEAN <2.0.0 - Info Disclosure
CVSS 8.2
CVE-2026-21667
CRITICAL
Backup Server - Authenticated RCE
CVSS 9.9
CVE-2026-21666
CRITICAL
Backup Server - Authenticated RCE
CVSS 9.9
CVE-2026-3940
MEDIUM
Google Chrome <146.0.7680.71 - Auth Bypass
CVSS 5.3
CVE-2026-3939
MEDIUM
Google Chrome <146.0.7680.71 - Auth Bypass
CVSS 5.3
CVE-2026-3938
MEDIUM
Google Chrome <146.0.7680.71 - Info Disclosure
CVSS 4.3
CVE-2026-3934
MEDIUM
Google Chrome <146.0.7680.71 - Auth Bypass
CVSS 6.5
CVE-2026-3932
HIGH
Google Chrome Android <146.0.7680.71 - Auth Bypass
CVSS 7.5
CVE-2026-27591
CRITICAL
Winter CMS <1.0.477/1.1.12/1.2.12 - Privilege Escalation
CVSS 9.9
Details
Vulnerabilities
4,788