CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
6,224 vulnerabilities with CWE-284
CVE-2026-15704
CRITICAL
CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components
CVSS 9.8
CVE-2026-12702
MEDIUM
Octopus Server 2023.0.0-2026.2.13189: Unauthenticated Unauthorized Deployment via Project Triggers
CVE-2026-14603
HIGH
WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection
CVSS 7.5
CVE-2026-12688
MEDIUM
ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery
CVSS 6.5
CVE-2026-35425
HIGH
Azure API Management (APIM) Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-65760
CRITICAL
Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1
CVE-2026-65759
HIGH
Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1
CVE-2026-65758
HIGH
Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2
CVE-2026-65757
HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension
CVSS 8.1
CVE-2026-64876
HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension
CVSS 8.8
CVE-2026-64871
MEDIUM
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension
CVSS 5.4
CVE-2026-60372
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 - Unauth RCE via Thirdparty Jars
CVSS 9.8
CVE-2026-60371
HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via Physical Network Access
CVSS 8.0
CVE-2026-60369
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Remote Code Execution via Centralized Thirdparty Jars
CVSS 9.9
CVE-2026-60366
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-64796
CRITICAL
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension
CVSS 9.8
CVE-2026-64794
MEDIUM
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions
CVSS 6.5
CVE-2026-64793
CRITICAL
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions
CVSS 9.1
CVE-2026-64791
HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager
CVSS 8.8
CVE-2026-63685
HIGH
Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension
CVSS 8.8
CVE-2026-63684
HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension
CVSS 8.8
CVE-2026-63280
HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager
CVSS 8.8
CVE-2026-63265
HIGH
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints
CVSS 8.0
CVE-2026-63047
HIGH
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1
CVSS 7.5
CVE-2026-14322
MEDIUM
Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method
CVSS 5.3
Details
Vulnerabilities
6,224