CWE-284

CWE-284 · 14 records · 6 with a public proof-of-concept

Records the NVD classes under CWE-284, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-67979public PoC

    Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.1CVE-2026-16102

    A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.1CVE-2026-15230

    The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to discl

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2025-70962public PoC

    Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-16736

    The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has tur

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.3CVE-2026-18788public PoC

    A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The expl

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 6.5CVE-2026-14816

    The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for a

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 6.2CVE-2026-71204public PoC

    changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 5.9CVE-2026-16547

    The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does it check the capability of the requester, allowing unauthenticated users in possession of any such token to do

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 5.4CVE-2026-70481public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checking that the caller wrot

    AI risk analysis on Exploit-DB.ai →

  11. MEDIUM 5.4CVE-2026-14848

    The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, allowing any authenticated user with Subscriber-level access and above t

    AI risk analysis on Exploit-DB.ai →

  12. MEDIUM 4.3CVE-2026-16295

    The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subscriber to render admin-only settings pages and disclose their contents, including admini

    AI risk analysis on Exploit-DB.ai →

  13. MEDIUM 4.3CVE-2026-12698

    The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-level account to write administrator-controlled account-state and reputation fields on their

    AI risk analysis on Exploit-DB.ai →

  14. UNSCOREDCVE-2026-70476public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organi

    AI risk analysis on Exploit-DB.ai →