CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,270 vulnerabilities with CWE-284
CVE-2026-1170
MEDIUM
birkir prime < 0.4.0 - Information Disclosure via GraphQL API
CVSS 5.3
CVE-2026-23522
LOW
LobeChat <2.0.0-next.193 - Privilege Escalation
CVSS 3.7
CVE-2026-1181
CRITICAL
Altium 365 - Improper Access Control via Overly Permissive CORS Policy
CVSS 9.0
CVE-2026-1152
MEDIUM
technical-laohu mpay < 1.2.4 - Unrestricted File Upload via QR Code Image Handler
CVSS 4.7
CVE-2026-1126
MEDIUM
LWJ Flow - Unrestricted File Upload in SVG File Handler
CVSS 6.3
CVE-2026-1107
MEDIUM
EyouCMS <1.7.1/5.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-1061
MEDIUM
xiweicheng TMS <2.28.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-1009
CRITICAL
Altium Live - Authenticated Stored Cross-Site Scripting in Forum Post Content
CVSS 9.0
CVE-2026-23496
MEDIUM
Pimcore Web2Print Tools Bundle <6.1.1 - Privilege Escalation
CVSS 5.4
CVE-2026-23495
MEDIUM
Pimcore <2.2.3-1.7.16 - Info Disclosure
CVSS 4.3
CVE-2026-23494
MEDIUM
Pimcore <12.3.1-11.5.14 - Info Disclosure
CVSS 4.3
CVE-2026-22909
HIGH
SICK TDC-X401GL Firmware - Unauthenticated Improper Access Control
CVSS 7.5
CVE-2026-21889
HIGH
Weblate < 5.15.2 - Unauthenticated Screenshot Access via Direct HTTP Request
CVSS 7.5
CVE-2026-20949
HIGH
Microsoft Office Excel - Info Disclosure
CVSS 7.8
CVE-2026-20929
HIGH
Windows HTTP.sys - Privilege Escalation
CVSS 7.5
CVE-2026-20843
HIGH
Windows RRAS - Privilege Escalation
CVSS 7.8
CVE-2026-20839
MEDIUM
Windows Client-Side Caching - Info Disclosure
CVSS 5.5
CVE-2026-20825
MEDIUM
Windows 10 1809 and Windows Server 2019 < 10.0.17763.8276 - Authenticated Information Disclosure
CVSS 4.4
CVE-2026-0386
HIGH
Windows Server 2008-2025 - Unauthenticated Remote Code Execution via Deployment Services
CVSS 7.5
CVE-2026-0881
CRITICAL
Firefox and Thunderbird < 147.0 - Sandbox Escape via Messaging System Component
CVSS 10.0
CVE-2026-22033
MEDIUM
Label Studio < 1.22.0 - Stored Cross-Site Scripting via Custom Hotkeys
CVSS 5.4
CVE-2026-22605
MEDIUM
OpenProject < 16.6.3 - Improper Access Control via Meeting Details
CVSS 4.3
CVE-2026-22043
CRITICAL
RustFS 1.0.0-alpha.13-1.0.0-alpha.78 - Privilege Escalation via Flawed IAM deny_only Short-Circuit
CVSS 9.8
CVE-2026-21694
MEDIUM
Titra < 0.99.50 - Improper Access Control
CVSS 6.8
CVE-2026-0643
HIGH
projectworlds House Rental and Property Listing 1.0 - Unrestricted File Upload via Signup Image Parameter
CVSS 7.3
Details
Vulnerabilities
5,270