CWE-284
5,470 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,470)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vuln...Show more |
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php. |
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type. |
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.9 HIGH· v3 N/A· v2 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 9, 2026 Jun 9, 2026 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. |
1Microsoft 4Windows 11 24h2 Windows 11 25h2Windows 11 26h1+1 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.9 HIGH· v3 N/A· v2 Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. |
1Microsoft 3Windows 11 24h2 Windows 11 25h2Windows 11 26h1Jun 17, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jun 9, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. |
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector h...Show more |
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity. |
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity. |
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Affected versions:
Spring Framework 5.3.0 through 5.3.48. |
Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-co...Show more |
A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting Page. This manipulation of the argument e...Show more |
A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record Handler. Executing...Show more |
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows a...Show more |
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the chatflow update endpoint of FlowiseAI. The endpoint allows cl...Show more |
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the tool update endpoint of FlowiseAI. The endpoint allows authen...Show more |