CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,305 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 71 of 127
- CVE-2025-22157HIGHCVSS 8.8EG 8.82025-05-20
This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center …
- CVE-2025-2216MEDIUMCVSS 6.3EG 6.32025-03-12
A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the function UploadCrash of the file /crash/log/SaveCrash.ashx. The manipulation of the argum…
- CVE-2025-2218MEDIUMCVSS 5.3EG 5.32025-03-12
A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /api/system/other of the component Setting Handler. The manipulation leads to improper acce…
- CVE-2025-2219HIGHCVSS 7.3EG 7.32025-03-12
A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /api/upload/image. The manipulation of the argument file leads to unrestricted upload. The at…
- CVE-2025-22391MEDIUMCVSS 6.7EG 6.72025-11-11
Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may ena…
- CVE-2025-22426HIGHCVSS 7.8EG 7.82026-06-01
In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti…
- CVE-2025-2278MEDIUMCVSS 6.5EG 6.52025-03-13
Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authenticated user to access information about these requests via a known request ID.
- CVE-2025-2280HIGHCVSS 8.1EG 8.12025-03-13
Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass the browser extension restriction feature.
- CVE-2025-22844MEDIUMCVSS 4.3EG 4.32025-05-13
Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
- CVE-2025-22940CRITICALCVSS 9.1EG 9.12025-03-31
Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.
- CVE-2025-23048CRITICALCVSS 9.1EG 9.12025-07-10
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple v…
- CVE-2025-2306MEDIUMCVSS 5.9EG 5.92025-05-16
An Improper Access Control vulnerability was identified in the file download functionality. This vulnerability allows users to download sensitive documents without authentication, if the URL is known. The attack requires the attacker to…
- CVE-2025-23083HIGHCVSS 7.7EG 7.72025-01-22
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its cons…
- CVE-2025-23164MEDIUMCVSS 4.4EG 4.42025-05-19
A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the recipient of a "Share Livestream" link to maintain access to the corresponding livestream subsequent to such link becomin…
- CVE-2025-23203MEDIUMCVSS 5.5EG 5.52025-03-26
Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4 on several director endpoints of REST API. To reproduce this vulnerability an authenticat…
- CVE-2025-23242HIGHCVSS 7.3EG 7.32025-03-11
NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, or information disclosure.
- CVE-2025-23243MEDIUMCVSS 6.5EG 6.52025-03-11
NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to data tampering or denial of service.
- CVE-2025-23277HIGHCVSS 7.3EG 7.32025-08-02
NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds permitted under normal use cases. A successful exploit of this vulnerability might lead to…
- CVE-2025-23329HIGHCVSS 7.5EG 7.52025-09-17
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corruption by identifying and accessing the shared memory region used by the Python backend. A successful exploit of this vu…
- CVE-2025-2334MEDIUMCVSS 5.4EG 5.42025-03-15
A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the file /api/mjkj-chat/chat/ai/delete/chat of the component Chat History Handler. The manipul…
- CVE-2025-23365HIGHCVSS 7.8EG 7.82025-07-08
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow a…
- CVE-2025-23367MEDIUMCVSS 6.5EG 6.52025-01-30
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspe…
- CVE-2025-23389HIGHCVSS 8.4EG 8.42025-04-11
A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.1…
- CVE-2025-2348MEDIUMCVSS 4.3EG 4.32025-03-16
A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an unknown function of the file /mnt/extsd/event/ of the component HTTP/RTSP. The manipulation leads to information disclosu…
- CVE-2025-2350MEDIUMCVSS 6.3EG 6.32025-03-16
A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is some unknown functionality of the file /action/upload_file. The manipulation leads to unrestricted upload. Access to t…
- CVE-2025-24042HIGHCVSS 7.3EG 7.32025-02-11
Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
- CVE-2025-24076HIGHCVSS 7.3EG 7.32025-03-11
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-24088HIGHCVSS 7.5EG 7.52025-09-15
The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to override MDM-enforced settings from profiles.
- CVE-2025-24090LOWCVSS 3.3EG 3.32026-01-16
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's installed apps.
- CVE-2025-24165MEDIUMCVSS 5.5EG 5.52026-06-11
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.
- CVE-2025-24173HIGHCVSS 7.8EG 7.82025-03-31
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may b…
- CVE-2025-24193LOWCVSS 2.4EG 2.42025-03-31
This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.
- CVE-2025-24197MEDIUMCVSS 5.5EG 5.52025-09-15
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access sensitive user data.
- CVE-2025-24198MEDIUMCVSS 6.6EG 6.62025-03-31
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may…
- CVE-2025-24202MEDIUMCVSS 5.5EG 5.52025-03-31
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.
- CVE-2025-24205MEDIUMCVSS 5.5EG 5.52025-03-31
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive…
- CVE-2025-24214MEDIUMCVSS 5.5EG 5.52025-03-31
A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.
- CVE-2025-24215MEDIUMCVSS 5.5EG 5.52025-03-31
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.
- CVE-2025-24218MEDIUMCVSS 5.5EG 5.52025-03-31
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. An app may be able to access information about a user's contacts.
- CVE-2025-24229HIGHCVSS 7.4EG 7.42025-03-31
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A sandboxed app may be able to access sensitive user data.
- CVE-2025-24236MEDIUMCVSS 5.5EG 5.52025-03-31
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.
- CVE-2025-24241CRITICALCVSS 9.8EG 9.82025-03-31
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to trick a user into copying sensitive data to the pasteboard.
- CVE-2025-24248MEDIUMCVSS 5.0EG 5.02025-03-31
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to enumerate devices that have signed into the user's Apple Account.
- CVE-2025-24259CRITICALCVSS 9.8EG 9.82025-03-31
This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.
- CVE-2025-24272MEDIUMCVSS 6.8EG 6.82025-03-31
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.
- CVE-2025-24313MEDIUMCVSS 4.4EG 4.42025-08-12
Improper access control for some Device Plugins for Kubernetes software maintained by Intel before version 0.32.0 may allow a privileged user to potentially enable denial of service via local access.
- CVE-2025-24314LOWCVSS 2.2EG 2.22025-11-11
Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with a privileged user combined with a high com…
- CVE-2025-24323MEDIUMCVSS 6.5EG 6.52025-08-12
Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before version MR4_1.0b1 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2025-24365HIGHCVSS 8.1EG 8.12025-01-27
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can b…
- CVE-2025-24411HIGHCVSS 8.1EG 8.12025-02-11
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage thi…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →