CWE-284 · 7 357 записей
Improper Access Control
CVE этого класса
7 363 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2023-27350Готовый эксплойт | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Критическая9,8 | KEV | 100,0 % | 20 апр. 2023 г. |
99Срочно | CVE-2024-27348Готовый эксплойт | Apache HugeGraph-Server: Command execution in gremlinapache · hugegraph · CWE-284 | Критическая9,8 | KEV | 99,2 % | 22 апр. 2024 г. |
99Срочно | CVE-2012-4681Готовый эксплойт | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to oracle · jdk · CWE-284 | Критическая9,8 | KEV | 98,5 % | 27 авг. 2012 г. |
98Срочно | CVE-2023-24489Готовый эксплойт | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthentcitrix · sharefile storage zones controller · CWE-284 | Критическая9,8 | KEV | 97,3 % | 10 июл. 2023 г. |
98Срочно | CVE-2013-0422Готовый эксплойт | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanoracle · jdk · CWE-284 | Критическая9,8 | KEV | 97,0 % | 10 янв. 2013 г. |
98Срочно | CVE-2011-3544Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Критическая9,8 | KEV | 96,7 % | 19 окт. 2011 г. |
97Срочно | CVE-2012-1723Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,oracle · jdk · CWE-284 | Критическая9,8 | KEV | 93,7 % | 16 июн. 2012 г. |
97Срочно | CVE-2016-3427Готовый эксплойт | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Критическая9,8 | KEV | 92,3 % | 21 апр. 2016 г. |
96Срочно | CVE-2012-5076Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers toracle · jre · CWE-284 | Критическая9,8 | KEV | 91,3 % | 16 окт. 2012 г. |
95Срочно | CVE-2025-12480Готовый эксплойт | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages evengladinet · triofox · CWE-284 | Критическая9,1 | KEV | 95,4 % | 10 нояб. 2025 г. |
93Срочно | CVE-2023-26360Готовый эксплойт | Adobe ColdFusion Improper Access Control Arbitrary code executionadobe · coldfusion · CWE-284 | Высокая8,6 | KEV | 97,3 % | 23 мар. 2023 г. |
91Срочно | CVE-2026-21962Готовый эксплойт | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serveoracle · http server · CWE-284 | Критическая10,0 | KEV | 70,9 % | 20 янв. 2026 г. |
90Срочно | CVE-2019-1653Готовый эксплойт | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerabilitycisco · rv320 firmware · CWE-284 | Высокая7,5 | KEV | 99,9 % | 24 янв. 2019 г. |
90Срочно | CVE-2023-29298Готовый эксплойт | Adobe ColdFusion Improper Access Control Security feature bypassadobe · coldfusion · CWE-284 | Высокая7,5 | KEV | 99,8 % | 12 июл. 2023 г. |
90Срочно | CVE-2023-38205Готовый эксплойт | ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298adobe · coldfusion · CWE-284 | Высокая7,5 | KEV | 99,7 % | 14 сент. 2023 г. |
90Срочно | CVE-2025-33073Готовый эксплойт | Windows SMB Client Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-284 | Высокая8,8 | KEV | 82,7 % | 10 июн. 2025 г. |
89Срочно | CVE-2024-20767Готовый эксплойт | ColdFusion | Improper Access Control (CWE-284)adobe · coldfusion · CWE-284 | Высокая7,4 | KEV | 98,5 % | 18 мар. 2024 г. |
89Срочно | CVE-2014-3120Готовый эксплойт | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expelastic · elasticsearch · CWE-284 | Высокая8,1 | KEV | 88,6 % | 28 июл. 2014 г. |
85Срочно | CVE-2021-22941Готовый эксплойт | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely comprocitrix · sharefile storagezones controller · CWE-284 | Критическая9,8 | KEV | 53,6 % | 23 сент. 2021 г. |
83Срочно | CVE-2020-8193Готовый эксплойт | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Ccitrix · application delivery controller firmware · CWE-284 | Средняя6,5 | KEV | 88,4 % | 10 июл. 2020 г. |
81Срочно | CVE-2023-23752Готовый эксплойт | [20230201] - Core - Improper access check in webservice endpointsjoomla · joomla\! · CWE-284 | Средняя5,3 | KEV | 99,8 % | 16 февр. 2023 г. |
80Срочно | CVE-2022-23134Готовый эксплойт | Possible view of the setup pages by unauthenticated users if config file already existszabbix · zabbix · CWE-284 | Средняя5,3 | KEV | 95,3 % | 13 янв. 2022 г. |
75На этой неделе | CVE-2024-40766Готовый эксплойт | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorizedsonicwall · sonicos · CWE-284 | Критическая9,8 | KEV | 18,4 % | 23 авг. 2024 г. |
75На этой неделе | CVE-2026-48907Готовый эксплойт | Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5widgetfactorylimited · jce · CWE-284 | Критическая10,0 | KEV | 16,2 % | 5 июн. 2026 г. |
75На этой неделе | CVE-2026-34908Готовый эксплойт | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthui · unifi os server · CWE-284 | Критическая10,0 | KEV | 15,2 % | 21 мая 2026 г. |
- CVE-2023-2735099Срочно
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %papercut · papercut mf20 апр. 2023 г.
- CVE-2024-2734899Срочно
Apache HugeGraph-Server: Command execution in gremlin
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · hugegraph22 апр. 2024 г.
- CVE-2012-468199Срочно
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %oracle · jdk27 авг. 2012 г.
- CVE-2023-2448998Срочно
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthent
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %citrix · sharefile storage zones controller10 июл. 2023 г.
- CVE-2013-042298Срочно
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · jdk10 янв. 2013 г.
- CVE-2011-354498Срочно
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · jdk19 окт. 2011 г.
- CVE-2012-172397Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %oracle · jdk16 июн. 2012 г.
- CVE-2016-342797Срочно
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %oracle · jdk21 апр. 2016 г.
- CVE-2012-507696Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers t
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 91 %oracle · jre16 окт. 2012 г.
- CVE-2025-1248095Срочно
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 95 %gladinet · triofox10 нояб. 2025 г.
- CVE-2023-2636093Срочно
Adobe ColdFusion Improper Access Control Arbitrary code execution
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 97 %adobe · coldfusion23 мар. 2023 г.
- CVE-2026-2196291Срочно
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serve
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 71 %oracle · http server20 янв. 2026 г.
- CVE-2019-165390Срочно
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %cisco · rv320 firmware24 янв. 2019 г.
- CVE-2023-2929890Срочно
Adobe ColdFusion Improper Access Control Security feature bypass
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %adobe · coldfusion12 июл. 2023 г.
- CVE-2023-3820590Срочно
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %adobe · coldfusion14 сент. 2023 г.
- CVE-2025-3307390Срочно
Windows SMB Client Elevation of Privilege Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %microsoft · windows 10 150710 июн. 2025 г.
- CVE-2024-2076789Срочно
ColdFusion | Improper Access Control (CWE-284)
ВысокаяCVSS 7,4KEVГотовый эксплойтEPSS 99 %adobe · coldfusion18 мар. 2024 г.
- CVE-2014-312089Срочно
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL exp
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 89 %elastic · elasticsearch28 июл. 2014 г.
- CVE-2021-2294185Срочно
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compro
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 54 %citrix · sharefile storagezones controller23 сент. 2021 г.
- CVE-2020-819383Срочно
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and C
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 88 %citrix · application delivery controller firmware10 июл. 2020 г.
- CVE-2023-2375281Срочно
[20230201] - Core - Improper access check in webservice endpoints
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 100 %joomla · joomla\!16 февр. 2023 г.
- CVE-2022-2313480Срочно
Possible view of the setup pages by unauthenticated users if config file already exists
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 95 %zabbix · zabbix13 янв. 2022 г.
- CVE-2024-4076675На этой неделе
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 18 %sonicwall · sonicos23 авг. 2024 г.
- CVE-2026-4890775На этой неделе
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 16 %widgetfactorylimited · jce5 июн. 2026 г.
- CVE-2026-3490875На этой неделе
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 15 %ui · unifi os server21 мая 2026 г.