CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,085 vulnerabilities with CWE-284
CVE-2026-27975
CRITICAL
ajenti < 2.2.13 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2026-22728
MEDIUM
Bitnami Sealed Secrets - Privilege Escalation
CVSS 4.9
CVE-2026-3209
MEDIUM
fosrl Pangolin <1.15.4-s.3 - Auth Bypass
CVSS 6.3
CVE-2026-3187
MEDIUM
feiyuchuixue sz-boot-parent <=1.3.2-beta - Unrestricted Upload
CVSS 6.3
CVE-2026-27624
HIGH
coturn < 4.9.0 - Improper Access Control via IPv4-Mapped IPv6 Bypass
CVSS 7.2
CVE-2026-24896
MEDIUM
OpenEMR <8.0.0 - Broken Access Control
CVSS 6.5
CVE-2026-2768
CRITICAL
Firefox < 148 and Firefox ESR < 140.8 - Sandbox Escape via IndexedDB Storage
CVSS 10.0
CVE-2026-25966
MEDIUM
ImageMagick <7.1.2-15/6.9.13-40 - Auth Bypass
CVSS 5.9
CVE-2026-3025
HIGH
ShuoRen Smart Heating 1.0.0 - Unrestricted Upload
CVSS 7.3
CVE-2026-2983
HIGH
Student Result Management System 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-2979
MEDIUM
FastApiAdmin <2.2.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-2978
MEDIUM
FastApiAdmin <=2.2.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-2977
MEDIUM
FastApiAdmin <2.2.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-2976
MEDIUM
FastApiAdmin <2.2.0 - Info Disclosure
CVSS 4.3
CVE-2026-2975
MEDIUM
FastApiAdmin <2.2.0 - Info Disclosure
CVSS 5.3
CVE-2026-2938
HIGH
Student Result Management System 1.0 - Auth Bypass
CVSS 7.3
CVE-2026-2894
MEDIUM
funadmin <7.1.0-rc4 - Info Disclosure
CVSS 5.3
CVE-2026-27471
CRITICAL
ERP <=15.98.0/16.0.0-rc.1-16.6.0 - Auth Bypass
CVSS 9.1
CVE-2026-2861
MEDIUM
Foswiki < 2.1.11 - Exposure of Sensitive Information via Changes/Viewfile/Oops Component
CVSS 5.3
CVE-2026-2852
MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2851
MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2850
MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 6.3
CVE-2026-2849
MEDIUM
yeqifu warehouse - Privilege Escalation
CVSS 5.4
CVE-2026-21627
CRITICAL
Tassos Framework Plugin - Auth Bypass
CVE-2026-26977
MEDIUM
Frappe LMS <=2.44.0 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
5,085