CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,085 vulnerabilities with CWE-284
CVE-2026-0748 MEDIUM
Access bypass in Drupal 7 i18n_node translation UI
CVSS 4.3
CVE-2026-33622 HIGH
A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution
CVSS 8.8
CVE-2026-4875 MEDIUM
itsourcecode Free Hotel Reservation System index.php unrestricted upload
CVSS 4.7
CVE-2026-4830 MEDIUM
kalcaddle kodbox Public Share userShare.class.php add privilege escalation
CVSS 5.6
CVE-2026-4823 LOW
Enter Software Iperius Backup NTLM2 information disclosure
CVSS 2.5
CVE-2026-28895 MEDIUM
iOS and iPadOS < 26.4 - Unauthenticated Access to Biometrics-Gated Protected Apps
CVSS 4.6
CVE-2026-28880 MEDIUM
iOS and iPadOS < 18.7.7 - Unauthenticated App Enumeration via Permissions Issue
CVSS 6.5
CVE-2026-28876 HIGH
iOS and iPadOS < 18.7.7 - Unprotected User Data Exposure via Path Handling Issue
CVSS 7.5
CVE-2026-28863 MEDIUM
iOS and iPadOS < 26.4 - Unauthorized User Fingerprinting via Permissions Issue
CVSS 6.5
CVE-2026-28862 MEDIUM
macOS < 14.8.5, < 15.7.5, < 26.4 - Unprotected User Data Exposure via Log Entry Redaction
CVSS 5.3
CVE-2026-28856 MEDIUM
iOS and iPadOS < 26.4 - Unauthenticated Sensitive User Information Exposure via Locked Device
CVSS 4.6
CVE-2026-28855 HIGH
iOS and iPadOS < 26.3 - Unprotected User Data Exposure via Permissions Issue
CVSS 7.5
CVE-2026-28838 MEDIUM
macOS <14.8.5 - Privilege Escalation
CVSS 5.3
CVE-2026-28837 HIGH
macOS < 26.4 - Unprotected User Data Exposure via Logic Issue
CVSS 7.5
CVE-2026-28833 MEDIUM
iOS and iPadOS < 26.4 - Unauthenticated App Enumeration via Permissions Issue
CVSS 6.2
CVE-2026-28828 MEDIUM
macOS < 14.8.5, < 15.7.5, < 26.4 - Unprotected User Data Exposure via Permissions Issue
CVSS 5.3
CVE-2026-28824 MEDIUM
macOS <14.8.5 - Privilege Escalation
CVSS 5.3
CVE-2026-28823 MEDIUM
macOS < 26.4 - Unprotected System File Deletion via Path Handling Issue
CVSS 4.9
CVE-2026-28818 MEDIUM
macOS < 14.8.5, < 15.7.5, < 26.4 - Unprotected User Data Exposure via Logging Issue
CVSS 5.3
CVE-2026-20697 MEDIUM
macOS <14.8.5 - Privilege Escalation
CVSS 5.3
CVE-2026-20684 LOW
macOS < 26.4 - Gatekeeper Bypass via Permissions Issue
CVSS 3.3
CVE-2026-20632 MEDIUM
Apple macOS <26.4 - Info Disclosure
CVSS 5.3
CVE-2026-20622 HIGH
macOS < 15.7.4 and < 26.3 - Unprotected User Data Exposure via Temporary File Handling
CVSS 7.5
CVE-2026-33316 HIGH
Vikunja’s Improper Access Control Enables Bypass of Administrator-Imposed Account Disablement
CVSS 8.1
CVE-2026-33484 HIGH
Langflow has Unauthenticated IDOR on Image Downloads
CVSS 7.5
Details
Vulnerabilities 5,085