Vulnerabilities (CVE)

Filtered by CWE-284
Total 7911 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-28378 1 Grafana 1 Grafana 2026-07-10 N/A 3.1 LOW
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
CVE-2026-15319 2026-07-10 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 3126. A patch should be applied to remediate this issue.
CVE-2026-46733 1 Dell 1 Display And Peripheral Manager 2026-07-10 N/A 7.8 HIGH
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
CVE-2026-55112 1 Ui 38 Enterprise Network Video Recorder, Enterprise Network Video Recorder Core, Enterprise Network Video Recorder Core Firmware and 35 more 2026-07-10 N/A 7.5 HIGH
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
CVE-2026-55116 1 Ui 1 Unifi Connect 2026-07-09 N/A 9.0 CRITICAL
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
CVE-2026-15188 2026-07-09 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the function EditEmployeeProfileAPIView of the file accounts/api/views.py of the component Employee Dashboard Endpoint. This manipulation of the argument role causes improper access controls. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-58525 1 Microsoft 1 Edge Chromium 2026-07-09 N/A 8.2 HIGH
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-48955 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.5 MEDIUM
An improper access check allows unauthorized users to access workflow stage and transition information.
CVE-2026-48956 1 Joomla 1 Joomla\! 2026-07-09 N/A 5.0 MEDIUM
An improper access check allows users to display a list of modules in the frontend.
CVE-2026-48957 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows unauthorized users to access com_privacy datasets.
CVE-2026-48958 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
CVE-2026-48947 1 Joomla 1 Joomla\! 2026-07-09 N/A 4.9 MEDIUM
An improper access check allows privileged users to overwrite media files without editing permissions.
CVE-2026-48948 1 Joomla 1 Joomla\! 2026-07-09 N/A 8.8 HIGH
An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.
CVE-2026-55119 1 Ui 1 Unifi Talk Application 2026-07-09 N/A 8.1 HIGH
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
CVE-2024-38909 1 Std42 1 Elfinder 2026-07-09 N/A 9.8 CRITICAL
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
CVE-2024-35396 1 Totolink 2 Cp900l, Cp900l Firmware 2026-07-09 N/A 9.8 CRITICAL
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.
CVE-2024-22830 2026-07-09 N/A 5.3 MEDIUM
Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control when handling system resources. This allows a local attacker to escalate privileges from regular user to System or PPL level.
CVE-2023-47325 1 Silverpeas 1 Silverpeas 2026-07-09 N/A 5.4 MEDIUM
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
CVE-2023-43336 1 Sangoma 1 Freepbx 2026-07-09 N/A 8.8 HIGH
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.
CVE-2023-43141 1 Totolink 4 A3700r, A3700r Firmware, N600r and 1 more 2026-07-09 N/A 9.8 CRITICAL
TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.