Vulnerabilities (CVE)

Filtered by CWE-284
Total 5364 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-24816 1 Nokia 1 Mantaray Nm 2026-07-10 N/A 6.5 MEDIUM
Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.
CVE-2026-56335 2026-07-10 N/A 6.5 MEDIUM
Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can modify sensitive channel attributes such as public, allow_emulator, and security-related flags outside intended application routes.
CVE-2026-28378 1 Grafana 1 Grafana 2026-07-10 N/A 3.1 LOW
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
CVE-2026-15319 2026-07-10 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 3126. A patch should be applied to remediate this issue.
CVE-2026-46733 1 Dell 1 Display And Peripheral Manager 2026-07-10 N/A 7.8 HIGH
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
CVE-2026-55112 1 Ui 38 Enterprise Network Video Recorder, Enterprise Network Video Recorder Core, Enterprise Network Video Recorder Core Firmware and 35 more 2026-07-10 N/A 7.5 HIGH
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
CVE-2026-55116 1 Ui 1 Unifi Connect 2026-07-09 N/A 9.0 CRITICAL
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
CVE-2026-15188 2026-07-09 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the function EditEmployeeProfileAPIView of the file accounts/api/views.py of the component Employee Dashboard Endpoint. This manipulation of the argument role causes improper access controls. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-58525 1 Microsoft 1 Edge Chromium 2026-07-09 N/A 8.2 HIGH
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-48955 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.5 MEDIUM
An improper access check allows unauthorized users to access workflow stage and transition information.
CVE-2026-48956 1 Joomla 1 Joomla\! 2026-07-09 N/A 5.0 MEDIUM
An improper access check allows users to display a list of modules in the frontend.
CVE-2026-48957 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48958 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48947 1 Joomla 1 Joomla\! 2026-07-09 N/A 4.9 MEDIUM
An improper access check allows privileged users to overwrite media files without editing permissions.
CVE-2026-48948 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-54400 1 Ui 1 Unifi Access Application 2026-07-09 N/A 9.1 CRITICAL
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
CVE-2026-55119 1 Ui 1 Unifi Talk Application 2026-07-09 N/A 8.1 HIGH
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
CVE-2024-38909 1 Std42 1 Elfinder 2026-07-09 N/A 9.8 CRITICAL
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
CVE-2024-35396 1 Totolink 2 Cp900l, Cp900l Firmware 2026-07-09 N/A 9.8 CRITICAL
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.
CVE-2024-22830 2026-07-09 N/A 5.3 MEDIUM
Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control when handling system resources. This allows a local attacker to escalate privileges from regular user to System or PPL level.