VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1097 CVEsRSS

CVE-2026-36738Medium· 6.8
4mo ago

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes a UART interface that lacks authentication, authorization, or access control mechanisms. An attacker with physical ac…

▾ Sunlitu-speed · t18-21k_firmwareEPSS 0.33%via NVD
CVE-2026-20887High· 7.5
4mo ago

Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service

Improper access control for some Intel Vision software for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack ma…

▾ Twilightintel · visionEPSS 0.46%via NVD
CVE-2026-8233Medium· 4.6
4mo ago

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of complexity is needed for the attack. The …

▾ SunlitEPSS 0.20%via NVD
CVE-2026-8069High· 7.8PoC
4mo ago

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigu…

▾ Midnightacer · nitrosenseEPSS 0.17%via NVD
CVE-2026-20167High· 7.7
4mo ago

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is d…

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is d…

▾ Twilightcisco · iot_field_network_directorEPSS 0.27%via NVD
CVE-2026-24303Critical· 9.6
5mo ago

Microsoft Partner Center Elevation of Privilege Vulnerability

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Partner CenterEPSS 0.39%via CVEORG
CVE-2026-35244Medium· 5.2
5mo ago

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management)

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.24.0.000. Easily exploitable vulnerability allows high privileg…

▾ Sunlitoracle · hyperion_infrastructure_technologyEPSS 0.28%via NVD
CVE-2026-6492Medium· 5.3
5mo ago

A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea

A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint.…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-31843Critical· 9.8
5mo ago

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed v…

▾ MidnightEPSS 1.2%via NVD
CVE-2026-26183High· 7.8
5mo ago

Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability

Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows Server 2012EPSS 0.30%via CVEORG
CVE-2026-27914High· 7.8
5mo ago

Microsoft Management Console Elevation of Privilege Vulnerability

Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-33103Medium· 5.5
5mo ago

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft Dynamics 365 (on-premises) version 9.0EPSS 0.35%via CVEORG
CVE-2026-32214Medium· 5.5
5mo ago

Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability

Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-32220Medium· 4.4
5mo ago

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

▾ Sunlitmicrosoft · windows_11_24h2EPSS 0.34%via NVD
CVE-2026-5881Medium· 6.5
5mo ago

Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page

Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.29%via NVD
CVE-2026-5863High· 8.8
5mo ago

Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.40%via NVD
CVE-2026-39364High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query par…

▾ Midnightvitejs · viteEPSS 1.5%via NVD
CVE-2026-35172High· 7.5PoC
5mo ago

Distribution is a toolkit to pack, ship, store, and deliver container content

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: t…

▾ Midnightdistribution · distributionEPSS 0.67%via NVD
CVE-2026-5569High· 7.3
5mo ago

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the component Endpoint. The manipulation results in improper access controls. The attack may be perf…

▾ Twilighttechnostrobe · hi-led-wr120-g2_firmwareEPSS 0.70%via NVD
CVE-2026-5526High· 7.3
5mo ago

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The att…

▾ Twilighttenda · 4g03_pro_firmwareEPSS 0.65%via NVD
CVE-2017-20233Medium· 5.4
5mo ago

Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured…

Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-5484Medium· 5.3
5mo ago

A weakness has been identified in BookStackApp BookStack up to 26.03

A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argumen…

▾ SunlitEPSS 0.55%via NVD
CVE-2026-21711Medium· 5.3
6mo ago

A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running unde…

A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running unde…

▾ Sunlitnodejs · node.jsEPSS 0.18%via NVD
CVE-2026-30689Medium· 4.3
6mo ago

In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure

In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threate…

▾ Sunlitanjoy8 · blog.adminEPSS 0.33%via NVD
CVE-2026-20622High· 7.5
6mo ago

A privacy issue was addressed with improved handling of temporary files

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to capture a user's screen.

▾ Twilightapple · macosEPSS 0.32%via NVD
CVE-2026-4105Medium· 6.7
6mo ago

A flaw was found in systemd

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged use…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-3429Medium· 4.2
6mo ago

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions

A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to perform sensitive actions intended only for higher-assurance sessions. Specifically, an attacker who has already obta…

▾ Sunlitredhat · build_of_keycloakEPSS 0.32%via NVD
CVE-2026-21262High· 8.8
6mo ago

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · sql_server_2016EPSS 2.0%via NVD
CVE-2025-70363High· 7.5
6mo ago

Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.

Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.

▾ Twilightibexa · ez_platformEPSS 0.24%via NVD
CVE-2026-20007Medium· 5.8
6mo ago

A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network …

A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network …

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.23%via NVD
CWE-284 vulnerabilities (CVEs) — page 34 · VulnSea