CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,075 vulnerabilities with CWE-284
CVE-2026-11464
LOW
JeecgBoot User List Endpoint SysUserController.java queryPageList information disclosure
CVSS 3.1
CVE-2026-11459
LOW
SecureAge CatchPulse IOCTL saappctl.sys information disclosure
CVSS 3.3
CVE-2026-11458
MEDIUM
erzhongxmu JeeWMS Boot Actuator Endpoint actuator information disclosure
CVSS 5.3
CVE-2026-45776
MEDIUM
Open XDMoD has Broken Access Control via Client-Controlled Session Variable
CVSS 4.3
CVE-2026-45746
CRITICAL
Termix Vulnerable to Arbitrary Command Execution via Session Hijacking
CVSS 9.0
CVE-2026-11344
HIGH
code-projects Vehicle Management System New Driver Registration Form newdriver.php unrestricted upload
CVSS 7.3
CVE-2026-11333
MEDIUM
tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload
CVSS 6.3
CVE-2026-48907
CRITICAL
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
CVE-2026-11326
MEDIUM
OpenAI Atlas < 1.2025.288.15 - Improper Access Control
CVE-2026-11302
MEDIUM
Google Chrome for iOS < 149.0.7827.53 - Unauthenticated Discretionary Access Control Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-11277
MEDIUM
Google Chrome for iOS < 149.0.7827.53 - Discretionary Access Control Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-11275
MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-11274
MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via DOM Distiller
CVSS 4.3
CVE-2026-11258
MEDIUM
Google Chrome < 149.0.7827.53 - Discretionary Access Control Bypass via File System Access
CVSS 6.5
CVE-2026-11257
MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-11252
MEDIUM
Google Chrome < 149.0.7827.53 - Insufficient Policy Enforcement in Content Settings
CVSS 4.3
CVE-2026-11212
MEDIUM
Google Chrome < 149.0.7827.53 - Cross-Origin Data Leak via DevTools Policy Bypass
CVSS 4.3
CVE-2026-11210
MEDIUM
Google Chrome < 149.0.7827.53 - Discretionary Access Control Bypass via Crafted RAR File
CVSS 6.5
CVE-2026-11204
MEDIUM
Google Chrome on iOS < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-11197
MEDIUM
Google Chrome < 149.0.7827.53 - Same Origin Policy Bypass via Workers
CVSS 6.5
CVE-2026-11193
MEDIUM
Google Chrome < 149.0.7827.53 - Insufficient Policy Enforcement in Password Manager
CVSS 6.5
CVE-2026-11190
MEDIUM
Google Chrome < 149.0.7827.53 - Discretionary Access Control Bypass via Malicious Extension
CVSS 6.5
CVE-2026-11187
MEDIUM
Google Chrome < 149.0.7827.53 - Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.3
CVE-2026-11179
HIGH
Google Chrome < 149.0.7827.53 - Site Isolation Bypass via ORB
CVSS 8.8
CVE-2026-11135
MEDIUM
Google Chrome < 149.0.7827.53 - Insufficient Policy Enforcement in Autofill
CVSS 6.5
Details
Vulnerabilities
5,075