CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,075 vulnerabilities with CWE-284
CVE-2026-41277
HIGH
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
CVSS 8.8
CVE-2026-41270
HIGH
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
CVSS 7.1
CVE-2026-41243
MEDIUM
OpenLearn's pending forum posts remain publicly readable by direct ID when moderation mode is enabled
CVSS 5.4
CVE-2026-41166
HIGH
OpenRemote has Improper Access Control via updateUserRealmRoles function
CVSS 7.0
CVE-2026-31192
MEDIUM
Raindrop.io Bookmark Manager Web App 5.6.76.0 - Info Disclosure
CVSS 6.5
CVE-2026-22754
HIGH
ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules
CVSS 7.5
CVE-2026-35252
MEDIUM
Oracle Security Service 12.2.1.4.0 - Privilege Escalation
CVSS 6.4
CVE-2026-35251
HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
CVE-2026-35250
LOW
Oracle VM VirtualBox 7.2.6 - Authenticated Partial Denial of Service
CVSS 2.3
CVE-2026-35249
LOW
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 3.2
CVE-2026-35248
MEDIUM
Oracle VM VirtualBox 7.2.6 - Authenticated Unauthorized Data Access and Partial Denial of Service
CVSS 5.0
CVE-2026-35247
MEDIUM
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 6.0
CVE-2026-35246
HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
CVE-2026-35245
HIGH
Oracle VM VirtualBox 7.2.6 - Unauthenticated Denial of Service via RDP
CVSS 7.5
CVE-2026-35244
MEDIUM
Oracle Hyperion Infrastructure Technology 11.2.24.0.000 - Privilege Escalation
CVSS 5.2
CVE-2026-35243
HIGH
Oracle ADF 12.2.1.4.0 - Privilege Escalation
CVSS 7.8
CVE-2026-35242
HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
CVE-2026-35241
MEDIUM
Oracle PeopleSoft Enterprise CS Student Records 9.2 - Info Disclosure
CVSS 5.7
CVE-2026-35240
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2026-35239
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in Server: DML
CVSS 4.9
CVE-2026-35238
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-35237
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-35236
MEDIUM
MySQL Server 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0 - Authenticated Denial of Service in InnoDB
CVSS 4.9
CVE-2026-35235
MEDIUM
MySQL Server 9.0.0-9.6.0 - Authenticated Denial of Service in GIS Component
CVSS 4.9
CVE-2026-35234
MEDIUM
MySQL Server 9.0.0-9.6.0 - Authenticated Denial of Service in Server Partition Component
CVSS 4.9
Details
Vulnerabilities
5,075