Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-284 · Improper access controlDefinition on MITRE ↗Clear

35 results

CVE-2026-21962
2026-08-24
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Oracle

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

CWE-284 · Improper access control
Refsoracle.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-27
CVE-2026-56290
2026-07-07
Joomlack Page Builder Improper Access Control Vulnerability
Joomlack

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

CWE-284 · Improper access control
Refsjoomlack.frBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-10
CVE-2026-34908
2026-06-23
Ubiquiti UniFi OS Improper Access Control Vulnerability
Ubiquiti

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.

CWE-284 · Improper access control
Refscommunity.ui.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-06-26
CVE-2026-48907
2026-06-16
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
Widget Factory

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

CWE-284 · Improper access control
Refsjoomlacontenteditor.netjoomlacontenteditor.netBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-06-19
CVE-2026-35616
2026-04-06
Fortinet FortiClient EMS Improper Access Control Vulnerability
Fortinet

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

CWE-284 · Improper access control
RefsPlease adhere to Fortinet's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Fortinet products affected by this vulnerability. Apply any final mitigations provided by the vendor as soon as they become available. For more information please seenvd.nist.gov
Federal remediation due 2026-04-09
CVE-2025-31125
2026-01-22
Vite Vitejs Improper Access Control Vulnerability
Vite

Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.

CWE-200 · Information exposureCWE-284 · Improper access control
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seenvd.nist.gov
Federal remediation due 2026-02-12
CVE-2025-12480
2025-11-12
Gladinet Triofox Improper Access Control Vulnerability
Gladinet

Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.

CWE-284 · Improper access control
Refsaccess.triofox.comnvd.nist.gov
Federal remediation due 2025-12-03
CVE-2025-33073
2025-10-20
Microsoft Windows SMB Client Improper Access Control Vulnerability
Microsoft

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

CWE-284 · Improper access control
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-11-10
CVE-2025-59230
2025-10-14
Microsoft Windows Improper Access Control Vulnerability
Microsoft

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.

CWE-284 · Improper access control
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-11-04
CVE-2025-24989
2025-02-21
Microsoft Power Pages Improper Access Control Vulnerability
Microsoft

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.

CWE-284 · Improper access control
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-03-14
CVE-2024-20767
2024-12-16
Adobe ColdFusion Improper Access Control Vulnerability
Adobe

Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.

CWE-284 · Improper access control
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2025-01-06
CVE-2024-45519
2024-10-03
Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands.

CWE-284 · Improper access control
Refswiki.zimbra.comnvd.nist.gov
Federal remediation due 2024-10-24
CVE-2024-27348
2024-09-18
Apache HugeGraph-Server Improper Access Control Vulnerability
Apache

Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.

CWE-284 · Improper access control
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-10-09
CVE-2024-40766
2024-09-09
SonicWall SonicOS Improper Access Control VulnerabilityRansomware
SonicWall

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

CWE-284 · Improper access control
Refspsirt.global.sonicwall.comsonicwall.comnvd.nist.gov
Federal remediation due 2024-09-30
CVE-2023-7028
2024-05-01
GitLab Community and Enterprise Editions Improper Access Control Vulnerability
GitLab / GitLab CE/EE

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

CWE-284 · Improper access control
Refsabout.gitlab.comnvd.nist.gov
Federal remediation due 2024-05-22
CVE-2023-23752
2024-01-08
Joomla! Improper Access Control Vulnerability
Joomla!

Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.

CWE-284 · Improper access control
Refsdeveloper.joomla.orgnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-24489
2023-08-16
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
Citrix

Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated attacker to remotely compromise customer-managed ShareFile storage zones controllers.

CWE-284 · Improper access control
Refssupport.citrix.comnvd.nist.gov
Federal remediation due 2023-09-06
CVE-2023-38205
2023-07-20
Adobe ColdFusion Improper Access Control Vulnerability
Adobe

Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.

CWE-284 · Improper access control
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2023-08-10
CVE-2023-29298
2023-07-20
Adobe ColdFusion Improper Access Control Vulnerability
Adobe

Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.

CWE-284 · Improper access control
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2023-08-10
CVE-2016-8735
2023-05-12
Apache Tomcat Remote Code Execution Vulnerability
Apache

Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This CVE exists because this listener wasn't updated for consistency with the Oracle patched issues for CVE-2016-3427 which affected credential types.

CWE-284 · Improper access control
Refstomcat.apache.orgnvd.nist.gov
Federal remediation due 2023-06-02
CVE-2023-27350
2023-04-21
PaperCut MF/NG Improper Access Control VulnerabilityRansomware
PaperCut

PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.

CWE-284 · Improper access control
Refspapercut.comnvd.nist.gov
Federal remediation due 2023-05-12
CVE-2023-26360
2023-03-15
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.

CWE-284 · Improper access control
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2023-04-05
CVE-2016-7256
2022-05-25
Microsoft Windows Open Type Font Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2016-3393
2022-05-25
Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability
Microsoft

A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2021-22941
2022-03-25
Citrix ShareFile Improper Access Control VulnerabilityRansomware
Citrix

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2020-2506
2022-03-25
QNAP Helpdesk Improper Access Control Vulnerability
QNAP Systems

QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2015-1427
2022-03-25
Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
Elastic

The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2014-3120
2022-03-25
Elasticsearch Remote Code Execution Vulnerability
Elastic

Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2022-23134
2022-02-22
Zabbix Frontend Improper Access Control Vulnerability
Zabbix

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-03-08
CVE-2021-23874
2021-11-03
McAfee Total Protection (MTP) Improper Privilege Management Vulnerability
McAfee

McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2020-8196
2021-11-03
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-8193
2021-11-03
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2019-1653
2021-11-03
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
Cisco

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-4437
2021-11-03
Apache Shiro Code Execution Vulnerability
Apache

Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the "remember me" feature.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-3715
2021-11-03
ImageMagick Arbitrary File Deletion Vulnerability
ImageMagick

ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.

CWE-284 · Improper access control
Refsnvd.nist.gov
Federal remediation due 2022-05-03