CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,080 vulnerabilities with CWE-284
CVE-2026-1879 MEDIUM
Harvard University IQSS Dataverse Theme Customization ThemeAndWidgets.xhtml unrestricted upload
CVSS 6.3
CVE-2026-5261 HIGH
Shandong Hoteam InforCenter PLM BaseHandler.ashx uploadFileToIIS unrestricted upload
CVSS 7.3
CVE-2026-4947 HIGH
Insecure Direct Object Reference (IDOR) Leading to Signature Forgery in Foxit eSign
CVSS 7.1
CVE-2026-5215 MEDIUM
D-Link DNS-1550-04 network_mgr.cgi cgi_get_ipv6 access control
CVSS 4.3
CVE-2026-34733 MEDIUM
AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard
CVSS 6.5
CVE-2026-34381 HIGH
Admidio: Unauthenticated Access to Role-Restricted documents via neutralized .htaccess
CVSS 7.5
CVE-2026-33415 LOW
Discourse: Improper Access Control in discourse-ai Allows Unauthorized Category Content Exposure
CVSS 2.7
CVE-2026-5181 MEDIUM
SourceCodester Simple Doctors Appointment System ajax.php unrestricted upload
CVSS 6.3
CVE-2026-21711 MEDIUM
Node.js 25.x - Privilege Escalation
CVSS 5.3
CVE-2026-29872 HIGH
awesome-llm-apps e46690f - Info Disclosure
CVSS 8.2
CVE-2026-5124 LOW
osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control
CVSS 3.7
CVE-2026-29597 MEDIUM
DDSN Interactive Acora CMS 10.7.1 - Info Disclosure
CVSS 6.5
CVE-2026-5122 LOW
osrg GoBGP BGP OPEN Message bgp.go DecodeFromBytes access control
CVSS 3.7
CVE-2026-5107 MEDIUM
FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control
CVSS 4.2
CVE-2026-5003 MEDIUM
PromtEngineer localGPT Web api_server.py handle_index information disclosure
CVSS 5.3
CVE-2026-5001 HIGH
PromtEngineer localGPT server.py do_POST unrestricted upload
CVSS 7.3
CVE-2026-31950 MEDIUM
LibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chats
CVSS 5.3
CVE-2026-30689 HIGH
blog.admin <= 8.0 - Sensitive Data Exposure via getinfobytoken API
CVSS 7.5
CVE-2026-33890 CRITICAL
MyTube <1.8.71 Passkey Registration - Admin Privilege Escalation
CVSS 9.8
CVE-2026-33726 MEDIUM
Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic
CVSS 5.4
CVE-2026-0748 MEDIUM
Access bypass in Drupal 7 i18n_node translation UI
CVSS 4.3
CVE-2026-33622 HIGH
A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution
CVSS 8.8
CVE-2026-4875 MEDIUM
itsourcecode Free Hotel Reservation System index.php unrestricted upload
CVSS 4.7
CVE-2026-4830 MEDIUM
kalcaddle kodbox Public Share userShare.class.php add privilege escalation
CVSS 5.6
CVE-2026-4823 LOW
Enter Software Iperius Backup NTLM2 information disclosure
CVSS 2.5
Details
Vulnerabilities 5,080