CWE-284 · 7.357 kayıt
Improper Access Control
Bu sınıftaki CVE’ler
7.363 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2023-27350Silahlaştırılmış | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).papercut · papercut mf · CWE-284 | Kritik9,8 | KEV | %100,0 | 20 Nis 2023 |
99Hemen | CVE-2024-27348Silahlaştırılmış | Apache HugeGraph-Server: Command execution in gremlinapache · hugegraph · CWE-284 | Kritik9,8 | KEV | %99,2 | 22 Nis 2024 |
99Hemen | CVE-2012-4681Silahlaştırılmış | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to oracle · jdk · CWE-284 | Kritik9,8 | KEV | %98,5 | 27 Ağu 2012 |
98Hemen | CVE-2023-24489Silahlaştırılmış | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthentcitrix · sharefile storage zones controller · CWE-284 | Kritik9,8 | KEV | %97,3 | 10 Tem 2023 |
98Hemen | CVE-2013-0422Silahlaştırılmış | Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanoracle · jdk · CWE-284 | Kritik9,8 | KEV | %97,0 | 10 Oca 2013 |
98Hemen | CVE-2011-3544Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Kritik9,8 | KEV | %96,7 | 19 Eki 2011 |
97Hemen | CVE-2012-1723Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,oracle · jdk · CWE-284 | Kritik9,8 | KEV | %93,7 | 16 Haz 2012 |
97Hemen | CVE-2016-3427Silahlaştırılmış | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Kritik9,8 | KEV | %92,3 | 21 Nis 2016 |
96Hemen | CVE-2012-5076Silahlaştırılmış | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers toracle · jre · CWE-284 | Kritik9,8 | KEV | %91,3 | 16 Eki 2012 |
95Hemen | CVE-2025-12480Silahlaştırılmış | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages evengladinet · triofox · CWE-284 | Kritik9,1 | KEV | %95,4 | 10 Kas 2025 |
93Hemen | CVE-2023-26360Silahlaştırılmış | Adobe ColdFusion Improper Access Control Arbitrary code executionadobe · coldfusion · CWE-284 | Yüksek8,6 | KEV | %97,3 | 23 Mar 2023 |
91Hemen | CVE-2026-21962Silahlaştırılmış | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serveoracle · http server · CWE-284 | Kritik10,0 | KEV | %70,9 | 20 Oca 2026 |
90Hemen | CVE-2019-1653Silahlaştırılmış | Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerabilitycisco · rv320 firmware · CWE-284 | Yüksek7,5 | KEV | %99,9 | 24 Oca 2019 |
90Hemen | CVE-2023-29298Silahlaştırılmış | Adobe ColdFusion Improper Access Control Security feature bypassadobe · coldfusion · CWE-284 | Yüksek7,5 | KEV | %99,8 | 12 Tem 2023 |
90Hemen | CVE-2023-38205Silahlaştırılmış | ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298adobe · coldfusion · CWE-284 | Yüksek7,5 | KEV | %99,7 | 14 Eyl 2023 |
90Hemen | CVE-2025-33073Silahlaştırılmış | Windows SMB Client Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-284 | Yüksek8,8 | KEV | %82,7 | 10 Haz 2025 |
89Hemen | CVE-2024-20767Silahlaştırılmış | ColdFusion | Improper Access Control (CWE-284)adobe · coldfusion · CWE-284 | Yüksek7,4 | KEV | %98,5 | 18 Mar 2024 |
89Hemen | CVE-2014-3120Silahlaştırılmış | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expelastic · elasticsearch · CWE-284 | Yüksek8,1 | KEV | %88,6 | 28 Tem 2014 |
85Hemen | CVE-2021-22941Silahlaştırılmış | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely comprocitrix · sharefile storagezones controller · CWE-284 | Kritik9,8 | KEV | %53,6 | 23 Eyl 2021 |
83Hemen | CVE-2020-8193Silahlaştırılmış | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Ccitrix · application delivery controller firmware · CWE-284 | Orta6,5 | KEV | %88,4 | 10 Tem 2020 |
81Hemen | CVE-2023-23752Silahlaştırılmış | [20230201] - Core - Improper access check in webservice endpointsjoomla · joomla\! · CWE-284 | Orta5,3 | KEV | %99,8 | 16 Şub 2023 |
80Hemen | CVE-2022-23134Silahlaştırılmış | Possible view of the setup pages by unauthenticated users if config file already existszabbix · zabbix · CWE-284 | Orta5,3 | KEV | %95,3 | 13 Oca 2022 |
75Bu hafta | CVE-2024-40766Silahlaştırılmış | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorizedsonicwall · sonicos · CWE-284 | Kritik9,8 | KEV | %18,4 | 23 Ağu 2024 |
75Bu hafta | CVE-2026-48907Silahlaştırılmış | Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5widgetfactorylimited · jce · CWE-284 | Kritik10,0 | KEV | %16,2 | 5 Haz 2026 |
75Bu hafta | CVE-2026-34908Silahlaştırılmış | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthui · unifi os server · CWE-284 | Kritik10,0 | KEV | %15,2 | 21 May 2026 |
- CVE-2023-2735099Hemen
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100papercut · papercut mf20 Nis 2023
- CVE-2024-2734899Hemen
Apache HugeGraph-Server: Command execution in gremlin
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · hugegraph22 Nis 2024
- CVE-2012-468199Hemen
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99oracle · jdk27 Ağu 2012
- CVE-2023-2448998Hemen
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthent
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97citrix · sharefile storage zones controller10 Tem 2023
- CVE-2013-042298Hemen
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBean
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97oracle · jdk10 Oca 2013
- CVE-2011-354498Hemen
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97oracle · jdk19 Eki 2011
- CVE-2012-172397Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94oracle · jdk16 Haz 2012
- CVE-2016-342797Hemen
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92oracle · jdk21 Nis 2016
- CVE-2012-507696Hemen
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers t
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %91oracle · jre16 Eki 2012
- CVE-2025-1248095Hemen
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %95gladinet · triofox10 Kas 2025
- CVE-2023-2636093Hemen
Adobe ColdFusion Improper Access Control Arbitrary code execution
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %97adobe · coldfusion23 Mar 2023
- CVE-2026-2196291Hemen
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serve
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %71oracle · http server20 Oca 2026
- CVE-2019-165390Hemen
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100cisco · rv320 firmware24 Oca 2019
- CVE-2023-2929890Hemen
Adobe ColdFusion Improper Access Control Security feature bypass
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100adobe · coldfusion12 Tem 2023
- CVE-2023-3820590Hemen
ColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100adobe · coldfusion14 Eyl 2023
- CVE-2025-3307390Hemen
Windows SMB Client Elevation of Privilege Vulnerability
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %83microsoft · windows 10 150710 Haz 2025
- CVE-2024-2076789Hemen
ColdFusion | Improper Access Control (CWE-284)
YüksekCVSS 7,4KEVSilahlaştırılmışEPSS %99adobe · coldfusion18 Mar 2024
- CVE-2014-312089Hemen
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL exp
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %89elastic · elasticsearch28 Tem 2014
- CVE-2021-2294185Hemen
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compro
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %54citrix · sharefile storagezones controller23 Eyl 2021
- CVE-2020-819383Hemen
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and C
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %88citrix · application delivery controller firmware10 Tem 2020
- CVE-2023-2375281Hemen
[20230201] - Core - Improper access check in webservice endpoints
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %100joomla · joomla\!16 Şub 2023
- CVE-2022-2313480Hemen
Possible view of the setup pages by unauthenticated users if config file already exists
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %95zabbix · zabbix13 Oca 2022
- CVE-2024-4076675Bu hafta
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %18sonicwall · sonicos23 Ağu 2024
- CVE-2026-4890775Bu hafta
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %16widgetfactorylimited · jce5 Haz 2026
- CVE-2026-3490875Bu hafta
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %15ui · unifi os server21 May 2026