CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

4,788 vulnerabilities with CWE-284
CVE-2026-41166 HIGH
OpenRemote has Improper Access Control via updateUserRealmRoles function
CVSS 7.0
CVE-2026-31192 MEDIUM
Raindrop.io Bookmark Manager Web App 5.6.76.0 - Info Disclosure
CVSS 6.5
CVE-2026-22754 HIGH
ervlet Path Not Correctly Included in Path Matching of XML Authorization Rules
CVSS 7.5
CVE-2026-35252 MEDIUM
Oracle Security Service 12.2.1.4.0 - Privilege Escalation
CVSS 6.4
CVE-2026-35251 HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
CVE-2026-35250 LOW
Oracle Corporation Oracle VM VirtualBox < 7.2.6 - Denial of Service
CVSS 2.3
CVE-2026-35249 LOW
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 3.2
CVE-2026-35248 MEDIUM
Oracle Corporation Oracle VM VirtualBox < 7.2.6 - Denial of Service
CVSS 5.0
CVE-2026-35247 MEDIUM
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 6.0
CVE-2026-35246 HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
CVE-2026-35245 HIGH
Oracle Corporation Oracle VM VirtualBox < 7.2.6 - Denial of Service
CVSS 7.5
CVE-2026-35244 MEDIUM
Oracle Hyperion Infrastructure Technology 11.2.24.0.000 - Privilege Escalation
CVSS 5.2
CVE-2026-35243 HIGH
Oracle ADF 12.2.1.4.0 - Privilege Escalation
CVSS 7.8
CVE-2026-35242 HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
CVE-2026-35241 MEDIUM
Oracle PeopleSoft Enterprise CS Student Records 9.2 - Info Disclosure
CVSS 5.7
CVE-2026-35240 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-35239 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-35238 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-35237 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-35236 MEDIUM
Oracle Corporation MySQL Server < 8.0.45 - Denial of Service
CVSS 4.9
CVE-2026-35235 MEDIUM
Oracle Corporation MySQL Server < 9.6.0 - Denial of Service
CVSS 4.9
CVE-2026-35234 MEDIUM
Oracle Corporation MySQL Server < 9.6.0 - Denial of Service
CVSS 4.9
CVE-2026-35232 MEDIUM
Oracle Fusion Middleware 12.2.1.4.0 - RCE
CVSS 5.4
CVE-2026-35231 HIGH
Oracle Financial Services Transaction Filtering 8.1.2.8.0 - Info Disclosure
CVSS 7.5
CVE-2026-35230 HIGH
Oracle VM VirtualBox 7.2.6 - Privilege Escalation
CVSS 7.5
Details
Vulnerabilities 4,788