Threats Tagged 'cwe-284'
View all threats tagged with 'cwe-284'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-284'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-19210: Unrestricted Upload in SourceCodester Photo Share WebsiteCVE-2026-19210 0 SourceCodester Photo Share Website 1.0 contains a vulnerability in the /social/ajax.php?action=save_upload endpoint. Manipulation of the img[] or imgName[] arguments allows unrestricted file upload. The vulnerability can be exploited remotely and public exploit details are available. No patch or remediation information is currently provided. Join the discussion | GCVE Database | 08/07/2026, 16:00:09 UTC Added: 08/08/2026, 14:52:18 UTC |
CVE-2026-19244: Improper Access Controls in HKUDS nanobotCVE-2026-19244 0 A vulnerability in HKUDS nanobot up to version 0.2.1 allows improper access control due to a flaw in the connect_mcp_servers function. This issue can be exploited remotely and has a public exploit available. The vulnerability is fixed by upgrading to version 0.3.0, which corrects the registration boundary of MCP resource and prompt wrappers to prevent unauthorized access. Join the discussion | GCVE Database | 08/07/2026, 20:30:13 UTC Added: 08/08/2026, 14:52:01 UTC |
CVE-2026-16948: CWE-284 Improper Access Control in Solace ExtraCVE-2026-16948 0 The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content. Join the discussion | CVE Database V5 | 08/08/2026, 09:30:21 UTC Added: 08/08/2026, 06:26:52 UTC |
CVE-2026-19192: Improper Access Controls in DeepCool DisplayServiceCVE-2026-19192 0 A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used. Join the discussion | GCVE Database | 08/07/2026, 03:45:08 UTC Added: 08/07/2026, 15:17:47 UTC |
CVE-2026-19195: Improper Access Controls in V-Secure Jingyun AntivirusCVE-2026-19195 0 A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | GCVE Database | 08/07/2026, 04:45:09 UTC Added: 08/07/2026, 15:17:46 UTC |
CVE-2026-12261: CWE-284 Improper Access Control in nltk nltk/nltkCVE-2026-12261 0 A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package integrity only after the archive has been written and extracted. This design flaw enables one package to overwrite another package's trusted resources within the same namespace, making the changes immediately active through ordinary NLTK APIs. This issue persists across fresh interpreter restarts and can affect downstream workflows, including machine learning pipelines and reproducibility-sensitive environments. Join the discussion | GCVE Database | 08/07/2026, 06:25:10 UTC Added: 08/07/2026, 15:17:43 UTC |
CVE-2026-54208: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54208 0 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the server with attacker-controlled content. This is possible because user input is written directly to files without proper validation or restriction on file types. As a result, an attacker can create files (e.g., .htm), containing malicious JavaScript code. When a user accesses a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524. Join the discussion | GCVE Database | 08/07/2026, 09:45:40 UTC Added: 08/07/2026, 15:17:33 UTC |
CVE-2026-66494: CWE-284 Improper Access Control in joomshaper.com SP Page Builder extension for JoomlaCVE-2026-66494 0 Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically.. Join the discussion | CVE Database V5 | 08/07/2026, 15:33:18 UTC Added: 08/07/2026, 13:26:45 UTC |
CVE-2026-54213: CWE-284 Improper Access Control in Tobit Laboratories AG TeamDavidCVE-2026-54213 0 Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524. Join the discussion | CVE Database V5 | 08/07/2026, 09:47:34 UTC Added: 08/07/2026, 10:12:17 UTC |
CVE-2026-54208: CWE-20 Improper input validation in Tobit Laboratories AG TeamDavidCVE-2026-54208 0 Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the server with attacker-controlled content. This is possible because user input is written directly to files without proper validation or restriction on file types. As a result, an attacker can create files (e.g., .htm), containing malicious JavaScript code. When a user accesses a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524. Join the discussion | CVE Database V5 | 08/07/2026, 09:45:40 UTC Added: 08/07/2026, 10:12:17 UTC |
Showing 1 to 10 of 160 results