CWE-284
7,824 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,824)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Xiweicheng 1Teamwork Management System Jun 17, 2026 Jan 17, 2026 2.1 LOW· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/controller/FileController.java. The manipulation of the argument filena...Show more |
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences. |
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's installed apps. |
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. A user may be able to view restricted content from the lock screen. |
This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive data. |
A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inject arbitrary JavaScript into forum posts...Show more |
Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for mana...Show more |
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Pre...Show more |
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for reading or listin...Show more |
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthori...Show more |
A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unin...Show more |
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations. |
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after...Show more |
Polkit authentication dis isabled by default and a race
condition in the Polkit authorization check in versions before v0.69.0 can
lead to the same issues as in CVE-2025-66005. |
n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming reque...Show more |
1Microsoft 2365 Apps Office Long Term Servicing ChannelJun 17, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. |
1Microsoft 11Windows 10 1607 Windows 10 1809Windows 10 21h2+8 moreJul 30, 2026 Jan 13, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJul 30, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
1Microsoft 14Windows 10 1607 Windows 10 1809Windows 10 21h2+11 moreJul 30, 2026 Jan 13, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. |
1Microsoft 10Windows 10 1809 Windows 10 21h2Windows 10 22h2+7 moreJul 30, 2026 Jan 13, 2026 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. |