CWE-284
CVEs classified under CWE-284, newest first.
1097 CVEsRSS
CVE-2026-58545Medium· 5.5Windows Kernel Security Feature Bypass Vulnerability
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
CVE-2026-57088High· 7.8Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
CVE-2026-50311High· 7.8Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
GHSA-7xw9-549r-8jrcHigh· 8.5DIRAC: SQL injection and lack of access control in PilotManager service
DIRAC: SQL injection and lack of access control in PilotManager service
CVE-2026-15539Medium· 4.7A security vulnerability has been detected in SourceCodester Online Book Store System 1.0
A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unr…
CVE-2026-15530Medium· 5.3A flaw has been found in WuzhiCMS up to 4.1.0
A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component Attachment API. Executing a manipulation can lead to inf…
CVE-2026-15518Medium· 4.7A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0
A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert…
CVE-2026-15488High· 7.3A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3
A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing a manipulation of the argument File can lead to unrestric…
CVE-2026-15476Medium· 5.3A security vulnerability has been detected in QILING Disk Master 6.0.0.0
A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The at…
CVE-2026-15475Medium· 5.3A weakness has been identified in MiniTool Partition Wizard up to 13.6
A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The …
CVE-2026-20744Critical· 9.8The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.
The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.
GHSA-382c-vx95-w3p5Medium· 6.5Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2026-58525High· 8.2Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
GHSA-7jvp-hj45-2f2mHighScriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
CVE-2025-71380High· 8.8The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentiall…
CVE-2026-58286High· 8.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58282High· 8.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58523Medium· 6.5Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-27779NoneGitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
CVE-2026-27660NoneGitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
CVE-2026-26292NoneGitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
CVE-2026-26247NoneGitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
CVE-2026-25712NoneGitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
CVE-2026-24690NoneGitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
CVE-2026-24451NoneGitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
CVE-2026-20909NoneGitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
CVE-2026-20896Critical· 9.8PoCGitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
CVE-2026-41123Medium· 4.3Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper acce…
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper acce…
CVE-2026-26145Medium· 4.8Microsoft Azure Synapse Elevation of Privilege Vulnerability
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
CVE-2026-50280MediumCraft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check