CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,085 vulnerabilities with CWE-284
CVE-2026-27975 CRITICAL
ajenti < 2.2.13 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2026-22728 MEDIUM
Bitnami Sealed Secrets - Privilege Escalation
CVSS 4.9
CVE-2026-3209 MEDIUM
fosrl Pangolin <1.15.4-s.3 - Auth Bypass
CVSS 6.3
CVE-2026-3187 MEDIUM
feiyuchuixue sz-boot-parent <=1.3.2-beta - Unrestricted Upload
CVSS 6.3
CVE-2026-27624 HIGH
coturn < 4.9.0 - Improper Access Control via IPv4-Mapped IPv6 Bypass
CVSS 7.2
CVE-2026-24896 MEDIUM
OpenEMR <8.0.0 - Broken Access Control
CVSS 6.5
CVE-2026-2768 CRITICAL
Firefox < 148 and Firefox ESR < 140.8 - Sandbox Escape via IndexedDB Storage
CVSS 10.0
CVE-2026-25966 MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Auth Bypass
CVSS 5.9
CVE-2026-3025 HIGH
ShuoRen Smart Heating 1.0.0 - Unrestricted Upload
CVSS 7.3
CVE-2026-2983 HIGH
Student Result Management System 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-2979 MEDIUM
FastApiAdmin <2.2.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-2978 MEDIUM
FastApiAdmin <=2.2.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-2977 MEDIUM
FastApiAdmin <2.2.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-2976 MEDIUM
FastApiAdmin <2.2.0 - Info Disclosure
CVSS 4.3
CVE-2026-2975 MEDIUM
FastApiAdmin <2.2.0 - Info Disclosure
CVSS 5.3
CVE-2026-2938 HIGH
Student Result Management System 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-2894 MEDIUM
funadmin <7.1.0-rc4 - Info Disclosure
CVSS 5.3
CVE-2026-27471 CRITICAL
ERP <=15.98.0/16.0.0-rc.1-16.6.0 - Auth Bypass
CVSS 9.1
CVE-2026-2861 MEDIUM
Foswiki < 2.1.11 - Exposure of Sensitive Information via Changes/Viewfile/Oops Component
CVSS 5.3
CVE-2026-2852 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2851 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2850 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2849 MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 5.4
CVE-2026-21627 CRITICAL
Tassos Framework Plugin - Auth Bypass
CVE-2026-26977 MEDIUM
Frappe LMS <=2.44.0 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 5,085