CWE-284 · 7,357 records
Improper Access Control
CVEs in this class
7,363 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2023-27350Weaponized | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Critical9.8 | KEV | 100.0% | Apr 20, 2023 |
99Now | CVE-2024-27348Weaponized | Apache HugeGraph-Server: Command execution in gremlinapache · hugegraph · CWE-284 | Critical9.8 | KEV | 99.2% | Apr 22, 2024 |
99Now | CVE-2012-4681Weaponized | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to oracle · jdk · CWE-284 | Critical9.8 | KEV | 98.5% | Aug 27, 2012 |
98Now | CVE-2023-24489Weaponized | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthentcitrix · sharefile storage zones controller · CWE-284 | Critical9.8 | KEV | 97.3% | Jul 10, 2023 |
98Now | CVE-2013-0422Weaponized | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanoracle · jdk · CWE-284 | Critical9.8 | KEV | 97.0% | Jan 10, 2013 |
98Now | CVE-2011-3544Weaponized | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Critical9.8 | KEV | 96.7% | Oct 19, 2011 |
97Now | CVE-2012-1723Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,oracle · jdk · CWE-284 | Critical9.8 | KEV | 93.7% | Jun 16, 2012 |
97Now | CVE-2016-3427Weaponized | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Critical9.8 | KEV | 92.3% | Apr 21, 2016 |
96Now | CVE-2012-5076Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers toracle · jre · CWE-284 | Critical9.8 | KEV | 91.3% | Oct 16, 2012 |
95Now | CVE-2025-12480Weaponized | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages evengladinet · triofox · CWE-284 | Critical9.1 | KEV | 95.4% | Nov 10, 2025 |
93Now | CVE-2023-26360Weaponized | Adobe ColdFusion Improper Access Control Arbitrary code executionadobe · coldfusion · CWE-284 | High8.6 | KEV | 97.3% | Mar 23, 2023 |
91Now | CVE-2026-21962Weaponized | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serveoracle · http server · CWE-284 | Critical10.0 | KEV | 70.9% | Jan 20, 2026 |
90Now | CVE-2019-1653Weaponized | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerabilitycisco · rv320 firmware · CWE-284 | High7.5 | KEV | 99.9% | Jan 24, 2019 |
90Now | CVE-2023-29298Weaponized | Adobe ColdFusion Improper Access Control Security feature bypassadobe · coldfusion · CWE-284 | High7.5 | KEV | 99.8% | Jul 12, 2023 |
90Now | CVE-2023-38205Weaponized | ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298adobe · coldfusion · CWE-284 | High7.5 | KEV | 99.7% | Sep 14, 2023 |
90Now | CVE-2025-33073Weaponized | Windows SMB Client Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-284 | High8.8 | KEV | 82.7% | Jun 10, 2025 |
89Now | CVE-2024-20767Weaponized | ColdFusion | Improper Access Control (CWE-284)adobe · coldfusion · CWE-284 | High7.4 | KEV | 98.5% | Mar 18, 2024 |
89Now | CVE-2014-3120Weaponized | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expelastic · elasticsearch · CWE-284 | High8.1 | KEV | 88.6% | Jul 28, 2014 |
85Now | CVE-2021-22941Weaponized | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely comprocitrix · sharefile storagezones controller · CWE-284 | Critical9.8 | KEV | 53.6% | Sep 23, 2021 |
83Now | CVE-2020-8193Weaponized | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Ccitrix · application delivery controller firmware · CWE-284 | Medium6.5 | KEV | 88.4% | Jul 10, 2020 |
81Now | CVE-2023-23752Weaponized | [20230201] - Core - Improper access check in webservice endpointsjoomla · joomla\! · CWE-284 | Medium5.3 | KEV | 99.8% | Feb 16, 2023 |
80Now | CVE-2022-23134Weaponized | Possible view of the setup pages by unauthenticated users if config file already existszabbix · zabbix · CWE-284 | Medium5.3 | KEV | 95.3% | Jan 13, 2022 |
75This week | CVE-2024-40766Weaponized | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorizedsonicwall · sonicos · CWE-284 | Critical9.8 | KEV | 18.4% | Aug 23, 2024 |
75This week | CVE-2026-48907Weaponized | Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5widgetfactorylimited · jce · CWE-284 | Critical10.0 | KEV | 16.2% | Jun 5, 2026 |
75This week | CVE-2026-34908Weaponized | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthui · unifi os server · CWE-284 | Critical10.0 | KEV | 15.2% | May 21, 2026 |
- CVE-2023-2735099Now
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%papercut · papercut mfApr 20, 2023
- CVE-2024-2734899Now
Apache HugeGraph-Server: Command execution in gremlin
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · hugegraphApr 22, 2024
- CVE-2012-468199Now
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to
CriticalCVSS 9.8KEVWeaponizedEPSS 99%oracle · jdkAug 27, 2012
- CVE-2023-2448998Now
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthent
CriticalCVSS 9.8KEVWeaponizedEPSS 97%citrix · sharefile storage zones controllerJul 10, 2023
- CVE-2013-042298Now
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · jdkJan 10, 2013
- CVE-2011-354498Now
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · jdkOct 19, 2011
- CVE-2012-172397Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,
CriticalCVSS 9.8KEVWeaponizedEPSS 94%oracle · jdkJun 16, 2012
- CVE-2016-342797Now
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
CriticalCVSS 9.8KEVWeaponizedEPSS 92%oracle · jdkApr 21, 2016
- CVE-2012-507696Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers t
CriticalCVSS 9.8KEVWeaponizedEPSS 91%oracle · jreOct 16, 2012
- CVE-2025-1248095Now
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even
CriticalCVSS 9.1KEVWeaponizedEPSS 95%gladinet · triofoxNov 10, 2025
- CVE-2023-2636093Now
Adobe ColdFusion Improper Access Control Arbitrary code execution
HighCVSS 8.6KEVWeaponizedEPSS 97%adobe · coldfusionMar 23, 2023
- CVE-2026-2196291Now
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serve
CriticalCVSS 10.0KEVWeaponizedEPSS 71%oracle · http serverJan 20, 2026
- CVE-2019-165390Now
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 100%cisco · rv320 firmwareJan 24, 2019
- CVE-2023-2929890Now
Adobe ColdFusion Improper Access Control Security feature bypass
HighCVSS 7.5KEVWeaponizedEPSS 100%adobe · coldfusionJul 12, 2023
- CVE-2023-3820590Now
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
HighCVSS 7.5KEVWeaponizedEPSS 100%adobe · coldfusionSep 14, 2023
- CVE-2025-3307390Now
Windows SMB Client Elevation of Privilege Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 83%microsoft · windows 10 1507Jun 10, 2025
- CVE-2024-2076789Now
ColdFusion | Improper Access Control (CWE-284)
HighCVSS 7.4KEVWeaponizedEPSS 99%adobe · coldfusionMar 18, 2024
- CVE-2014-312089Now
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL exp
HighCVSS 8.1KEVWeaponizedEPSS 89%elastic · elasticsearchJul 28, 2014
- CVE-2021-2294185Now
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compro
CriticalCVSS 9.8KEVWeaponizedEPSS 54%citrix · sharefile storagezones controllerSep 23, 2021
- CVE-2020-819383Now
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and C
MediumCVSS 6.5KEVWeaponizedEPSS 88%citrix · application delivery controller firmwareJul 10, 2020
- CVE-2023-2375281Now
[20230201] - Core - Improper access check in webservice endpoints
MediumCVSS 5.3KEVWeaponizedEPSS 100%joomla · joomla\!Feb 16, 2023
- CVE-2022-2313480Now
Possible view of the setup pages by unauthenticated users if config file already exists
MediumCVSS 5.3KEVWeaponizedEPSS 95%zabbix · zabbixJan 13, 2022
- CVE-2024-4076675This week
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized
CriticalCVSS 9.8KEVWeaponizedEPSS 18%sonicwall · sonicosAug 23, 2024
- CVE-2026-4890775This week
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
CriticalCVSS 10.0KEVWeaponizedEPSS 16%widgetfactorylimited · jceJun 5, 2026
- CVE-2026-3490875This week
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth
CriticalCVSS 10.0KEVWeaponizedEPSS 15%ui · unifi os serverMay 21, 2026