CWE-284
7,447 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (7,447)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE:...Show more |
2Debian Python2Debian Linux PillowMay 6, 2026 Nov 4, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. |
Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user permission. But, the method name in PHP reflection is case insensitive, and Exponent CMS permits un...Show more |
1Ibm 1Financial Transaction Manager May 6, 2026 Oct 29, 2016 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to c...Show more |
1Alienvault 2Open Source Security Information And Event Management Unified Security ManagementMay 6, 2026 Oct 28, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes. |
1Oracle 1Peoplesoft Enterprise Peopletools May 6, 2026 Oct 25, 2016 N/A· v4 7.6 HIGH· v3 4.9 MEDIUM· v2 Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to LD...Show more |
1Oracle 1Peoplesoft Enterprise Peopletools May 6, 2026 Oct 25, 2016 N/A· v4 8.2 HIGH· v3 5.8 MEDIUM· v2 Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration...Show more |
1Oracle 1Peoplesoft Enterprise Human Capital Management Talent Acquisition Manager May 6, 2026 Oct 25, 2016 N/A· v4 4.2 MEDIUM· v3 5.8 MEDIUM· v2 Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Talent Acquisition M...Show more |
1Oracle 1Peoplesoft Enterprise Peopletools May 6, 2026 Oct 25, 2016 N/A· v4 8.2 HIGH· v3 5.8 MEDIUM· v2 Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Mobile Appli...Show more |
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect integrity via vectors related to Server: InnoDB Plugin. |
1Oracle 1Peoplesoft Enterprise Human Capital Management Candidate Gateway May 6, 2026 Oct 25, 2016 N/A· v4 4.8 MEDIUM· v3 4.9 MEDIUM· v2 Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway. |
1Oracle 1Platform Security For Java May 6, 2026 Oct 25, 2016 N/A· v4 7.6 HIGH· v3 6.5 MEDIUM· v2 Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and...Show more |
1Oracle 1Flexcube Universal Banking May 6, 2026 Oct 25, 2016 N/A· v4 6.1 MEDIUM· v3 7.8 HIGH· v2 Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote attackers to affect confident...Show more |
1Oracle 1Flexcube Universal Banking May 6, 2026 Oct 25, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 and 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect con...Show more |
1Oracle 1Flexcube Universal Banking May 6, 2026 Oct 25, 2016 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect...Show more |
1Oracle 1Flexcube Universal Banking May 6, 2026 Oct 25, 2016 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect...Show more |
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Lynx. |
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerabili...Show more |
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related...Show more |
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerabili...Show more |