The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Volume of CVEs assigned to CWE-284 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
5,804 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27348CRITICAL RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11
Users are recommended t | Apr 22, 2024 | 9.8 | 99 | YES | YES |
CVE-2023-27350CRITICAL This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vu | Apr 20, 2023 | 9.8 | 99 | YES | YES |
CVE-2026-48907CRITICAL A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | Jun 5, 2026 | 9.8 | 98 | YES | YES |
CVE-2026-35616CRITICAL A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted re | Apr 4, 2026 | 9.8 | 98 | YES | YES |
CVE-2024-20767HIGH ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage | Mar 18, 2024 | 7.4 | 98 | YES | YES |
CVE-2023-26360CRITICAL Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code | Mar 23, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-23752MEDIUM An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | Feb 16, 2023 | 5.3 | 98 | YES | YES |
CVE-2019-1653HIGH A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrie | Jan 24, 2019 | 7.5 | 98 | YES | YES |
CVE-2013-0422CRITICAL Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServe | Jan 10, 2013 | 9.8 | 98 | YES | YES |
CVE-2012-5076CRITICAL Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and | Oct 16, 2012 | 9.8 | 98 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.