← Back
CWE-284

7,447 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,447)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
1Shipping Execution
May 6, 2026
Oct 25, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Oracle Shipping Execution component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality via vectors related to Wor...Show more
Unspecified vulnerability in the Oracle Shipping Execution component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality via vectors related to Workflow Events.Show less
1Oracle
1Agile Product Lifecycle Management
May 6, 2026
Oct 25, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-...Show more
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5524.Show less
1Oracle
1Agile Product Lifecycle Management
May 6, 2026
Oct 25, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Apac...Show more
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Apache Tomcat.Show less
1Oracle
1Solaris Cluster
May 6, 2026
Oct 25, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect integrity via vectors related to Cluster check files.
1Oracle
1Agile Product Lifecycle Management
May 6, 2026
Oct 25, 2016
N/A· v4
6.5 MEDIUM· v3
7.5 HIGH· v2
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerabi...Show more
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5512.Show less
1Oracle
1Applications Dba
May 6, 2026
Oct 25, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.1.3 allows local users to affect confidentiality via vectors related to AD Utilities.
1Oracle
1Identity Manager
May 6, 2026
Oct 25, 2016
N/A· v4
3.1 LOW· v3
3.3 LOW· v2
Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware allows local users to affect confidentiality and integrity via vectors related to App Server.
1Oracle
1Flexcube Universal Banking
May 6, 2026
Oct 25, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality and...Show more
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to INFRA.Show less
1Oracle
1Database
May 6, 2026
Oct 25, 2016
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
1Oracle
1Discoverer
May 6, 2026
Oct 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality via vectors related to EUL Code & Schema.
1Oracle
1Flexcube Private Banking
May 6, 2026
Oct 25, 2016
N/A· v4
4.2 MEDIUM· v3
4.9 MEDIUM· v2
Unspecified vulnerability in the Oracle FLEXCUBE Private Banking component in Oracle Financial Services Applications 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality and integrity via unk...Show more
Unspecified vulnerability in the Oracle FLEXCUBE Private Banking component in Oracle Financial Services Applications 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.Show less
1Oracle
1Sun Zfs Storage Appliance Kit
May 6, 2026
Oct 25, 2016
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affect confidentiality and integrity via vectors related to SMB Users.
1Oracle
1Commerce Service Center
May 6, 2026
Oct 25, 2016
N/A· v4
8.2 HIGH· v3
5.8 MEDIUM· v2
Unspecified vulnerability in the Oracle Commerce Service Center component in Oracle Commerce 10.0.3.5 and 10.2.0.5 allows remote attackers to affect confidentiality and integrity via unknown vectors.
1Oracle
1Commerce Guided Search
May 6, 2026
Oct 25, 2016
N/A· v4
8.2 HIGH· v3
5.8 MEDIUM· v2
Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confidentiality and integrity via unknown vecto...Show more
Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.Show less
1Python
1Tgcaptcha2
May 6, 2026
Oct 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.
1Apache
1Commons Fileupload
May 6, 2026
Oct 25, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
1Ibm
1Security Guardium Database Activity Monitor
May 6, 2026
Oct 22, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified logi...Show more
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP.Show less
1Microsoft
1Edge
May 6, 2026
Oct 14, 2016
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
The Edge Content Security Policy feature in Microsoft Edge does not properly validate documents, which allows remote attackers to bypass intended access restrictions via a crafted web site, aka "Microsoft Browser Securit...Show more
The Edge Content Security Policy feature in Microsoft Edge does not properly validate documents, which allows remote attackers to bypass intended access restrictions via a crafted web site, aka "Microsoft Browser Security Feature Bypass Vulnerability."Show less
1Microsoft
5Windows 10
Windows 7Windows 8.1+2 more
May 6, 2026
Oct 14, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Video...Show more
Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Video Control Remote Code Execution Vulnerability."Show less
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 6, 2026
Oct 13, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to bypass intended...Show more
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to bypass intended access restrictions via unspecified vectors.Show less