VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 303 of 327
  • CVE-2026-46954HigJul 21, 2026
    risk 0.00cvss 7.2epss 0.00

    Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise…

  • CVE-2026-46941HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-46924CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.00

    Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this…

  • CVE-2026-46876CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.00

    Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. Successful attacks of…

  • CVE-2026-35290CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.00

    Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this…

  • CVE-2026-35287HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this…

  • CVE-2026-16451MedJul 21, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. Performing a manipulation of the argument…

  • CVE-2026-28321CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows…

  • CVE-2026-28307CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.

  • CVE-2026-28306CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.

  • CVE-2026-28304CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

  • CVE-2026-16447HigJul 21, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has…

  • CVE-2025-66390CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.00

    In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup…

  • CVE-2026-16332HigJul 21, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is…

  • CVE-2026-16331HigJul 21, 2026
    risk 0.00cvss 7.3epss 0.01

    A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has…

  • CVE-2026-16330HigJul 21, 2026
    risk 0.00cvss 7.3epss 0.01

    A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes…

  • CVE-2026-16329HigJul 21, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly…

  • CVE-2026-16327HigJul 21, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been…

  • CVE-2026-55550HigJul 20, 2026
    risk 0.00cvss 7.1epss 0.00

    NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, and deletion to `manager` and `admin` roles. However, in version 0.12.1,…

  • CVE-2026-55544HigJul 20, 2026
    risk 0.00cvss 7.6epss 0.00

    NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The application has an authorization model that…