CWE-284— Improper Access Control
4,229 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 37 of 85
- CVE-2024-0899MEDIUMCVSS 5.3EG 5.32024-04-09
The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via th…
- CVE-2024-0965MEDIUMCVSS 5.3EG 5.32024-02-08
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugi…
- CVE-2024-0969MEDIUMCVSS 5.3EG 5.32024-02-05
The ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Default Restricti…
- CVE-2024-0972MEDIUMCVSS 5.3EG 5.32024-06-06
The BuddyPress Members Only plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.9 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "All…
- CVE-2024-0975MEDIUMCVSS 5.3EG 5.32024-02-28
The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "…
- CVE-2024-0978MEDIUMCVSS 5.3EG 5.32024-02-29
The My Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.14 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's site privac…
- CVE-2024-1011MEDIUMCVSS 4.3EG 4.32024-01-29
A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the file delete-leave.php of the component Leave Handler. The manipulation of the argument id …
- CVE-2024-10124CRITICALCVSS 9.8EG 9.82024-12-12
The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions…
- CVE-2024-10241MEDIUMCVSS 4.3EG 4.32024-10-29
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
- CVE-2024-10272HIGHCVSS 7.5EG 7.52025-03-20
lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of authorization by sending a GET request to the /v1/datasets endpoint without a valid authoriz…
- CVE-2024-10275HIGHCVSS 7.3EG 7.32025-03-20
In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change the permissions of existing users to include billing permissions. This can lead to a priv…
- CVE-2024-10330MEDIUMCVSS 6.5EG 6.52025-03-20
In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of their role. This vulnerability permits low-privilege users…
- CVE-2024-10353MEDIUMCVSS 6.3EG 6.32024-10-25
A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown function of the file /admin-dashboard. The manipulation leads to improper access controls. It is possible to launch the …
- CVE-2024-10363MEDIUMCVSS 5.4EG 5.42025-03-20
In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowin…
- CVE-2024-10366MEDIUMCVSS 6.5EG 7.62025-03-20
An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowi…
- CVE-2024-10393MEDIUMCVSS 5.3EG 5.32024-11-21
The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6. This is due to a missing check for the 'users_can_register' option in the 'register_instructor' function. This makes i…
- CVE-2024-1044MEDIUMCVSS 5.3EG 5.32024-02-29
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submit_review' function in all versions up to, and including, 5.38.12. This makes it pos…
- CVE-2024-1053MEDIUMCVSS 4.3EG 4.32024-02-22
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authentica…
- CVE-2024-10764MEDIUMCVSS 6.3EG 6.32024-11-04
A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. I…
- CVE-2024-10765MEDIUMCVSS 6.3EG 6.32024-11-04
A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument old_image leads to unrestricted u…
- CVE-2024-10766MEDIUMCVSS 6.3EG 6.32024-11-04
A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image…
- CVE-2024-1088MEDIUMCVSS 5.3EG 5.32024-03-05
The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the REST API. This makes it possible for unauthenticated attackers to extract s…
- CVE-2024-10916MEDIUMCVSS 5.3EG 5.32024-11-06
A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the file /xml/info.xml of the component HTTP GET Request Handler. The manipulation …
- CVE-2024-1092MEDIUMCVSS 4.3EG 4.32024-02-05
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the feedzy dashboard in all versio…
- CVE-2024-10937MEDIUMCVSS 5.3EG 5.32024-12-05
The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.58 via the wp_ajax_nopriv_rela…
- CVE-2024-10956HIGHCVSS 7.1EG 7.62025-03-20
GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and…
- CVE-2024-10965MEDIUMCVSS 4.3EG 4.32024-11-07
A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to informatio…
- CVE-2024-10993MEDIUMCVSS 6.3EG 6.32024-11-08
A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affected is an unknown function of the file /manage_website.php. The manipulation of the argument website_image leads to unres…
- CVE-2024-10994MEDIUMCVSS 6.3EG 6.32024-11-08
A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit_user.php. The manipulation of the argument image lea…
- CVE-2024-10999MEDIUMCVSS 4.7EG 4.72024-11-08
A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the argument aimage lead…
- CVE-2024-11000MEDIUMCVSS 4.7EG 4.72024-11-08
A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutedit.php of the component About Us Page. The manipulation of t…
- CVE-2024-11045CRITICALCVSS 9.6EG 9.62025-03-20
A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of prop…
- CVE-2024-11054MEDIUMCVSS 6.3EG 6.32024-11-10
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unr…
- CVE-2024-11122MEDIUMCVSS 6.3EG 6.32024-11-12
A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this issue is some unknown functionality of the file /crm/wechatSession/index.php?msgid=1&ope…
- CVE-2024-11137HIGHCVSS 7.5EG 7.52025-03-20
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vulnerability allows an attacker to update the score data of any run by manipulating the id …
- CVE-2024-11138LOWCVSS 2.7EG 2.72024-11-12
A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possi…
- CVE-2024-1114MEDIUMCVSS 6.5EG 6.52024-01-31
A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function dlfile of the file /application/index/controller/Screen.php. The manipulation of the argument fileUrl leads to imprope…
- CVE-2024-11167MEDIUMCVSS 5.3EG 9.42025-03-20
An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether t…
- CVE-2024-11211MEDIUMCVSS 4.7EG 4.72024-11-14
A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotel…
- CVE-2024-11214MEDIUMCVSS 4.7EG 4.72024-11-14
A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument website_image leads t…
- CVE-2024-11300MEDIUMCVSS 6.5EG 8.82025-03-20
In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized user…
- CVE-2024-11358MEDIUMCVSS 5.7EG 5.72024-12-16
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.
- CVE-2024-1144MEDIUMCVSS 6.5EG 6.52024-03-19
Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an unauthenticated user to access the application's functionalities without the need for credentials.
- CVE-2024-11483MEDIUMCVSS 5.0EG 5.02024-11-25
A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on an…
- CVE-2024-11484MEDIUMCVSS 6.3EG 6.32024-11-20
A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /decoration/admin/update_image.php of the component User Image Handler.…
- CVE-2024-1153MEDIUMCVSS 4.6EG 4.32024-06-27
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Travel APPS: b…
- CVE-2024-11661MEDIUMCVSS 4.3EG 4.32024-11-25
A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file profile.php of the component Profile Image Handler. The manipulati…
- CVE-2024-11674MEDIUMCVSS 6.3EG 6.32024-11-26
A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an unknown function of the file /backend/doc/his_doc_update-account.php. The manipulation of the argument doc_dpic leads …
- CVE-2024-11868MEDIUMCVSS 5.3EG 5.32024-12-10
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. This makes it possible for unauthenticate…
- CVE-2024-11961MEDIUMCVSS 5.3EG 5.32024-11-28
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This issue affects the function preHandle of the file src/main/java/com/zzjee/wm/controller/WmOmNoticeHController.java. The m…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →