CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,080 vulnerabilities with CWE-284
CVE-2026-1879
MEDIUM
Harvard University IQSS Dataverse Theme Customization ThemeAndWidgets.xhtml unrestricted upload
CVSS 6.3
CVE-2026-5261
HIGH
Shandong Hoteam InforCenter PLM BaseHandler.ashx uploadFileToIIS unrestricted upload
CVSS 7.3
CVE-2026-4947
HIGH
Insecure Direct Object Reference (IDOR) Leading to Signature Forgery in Foxit eSign
CVSS 7.1
CVE-2026-5215
MEDIUM
D-Link DNS-1550-04 network_mgr.cgi cgi_get_ipv6 access control
CVSS 4.3
CVE-2026-34733
MEDIUM
AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard
CVSS 6.5
CVE-2026-34381
HIGH
Admidio: Unauthenticated Access to Role-Restricted documents via neutralized .htaccess
CVSS 7.5
CVE-2026-33415
LOW
Discourse: Improper Access Control in discourse-ai Allows Unauthorized Category Content Exposure
CVSS 2.7
CVE-2026-5181
MEDIUM
SourceCodester Simple Doctors Appointment System ajax.php unrestricted upload
CVSS 6.3
CVE-2026-21711
MEDIUM
Node.js 25.x - Privilege Escalation
CVSS 5.3
CVE-2026-29872
HIGH
awesome-llm-apps e46690f - Info Disclosure
CVSS 8.2
CVE-2026-5124
LOW
osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control
CVSS 3.7
CVE-2026-29597
MEDIUM
DDSN Interactive Acora CMS 10.7.1 - Info Disclosure
CVSS 6.5
CVE-2026-5122
LOW
osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control
CVSS 3.7
CVE-2026-5107
MEDIUM
FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control
CVSS 4.2
CVE-2026-5003
MEDIUM
PromtEngineer localGPT Web api_server.py handle_index information disclosure
CVSS 5.3
CVE-2026-5001
HIGH
PromtEngineer localGPT server.py do_POST unrestricted upload
CVSS 7.3
CVE-2026-31950
MEDIUM
LibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chats
CVSS 5.3
CVE-2026-30689
HIGH
blog.admin <= 8.0 - Sensitive Data Exposure via getinfobytoken API
CVSS 7.5
CVE-2026-33890
CRITICAL
MyTube <1.8.71 Passkey Registration - Admin Privilege Escalation
CVSS 9.8
CVE-2026-33726
MEDIUM
Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic
CVSS 5.4
CVE-2026-0748
MEDIUM
Access bypass in Drupal 7 i18n_node translation UI
CVSS 4.3
CVE-2026-33622
HIGH
A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution
CVSS 8.8
CVE-2026-4875
MEDIUM
itsourcecode Free Hotel Reservation System index.php unrestricted upload
CVSS 4.7
CVE-2026-4830
MEDIUM
kalcaddle kodbox Public Share userShare.class.php add privilege escalation
CVSS 5.6
CVE-2026-4823
LOW
Enter Software Iperius Backup NTLM2 information disclosure
CVSS 2.5
Details
Vulnerabilities
5,080