CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,309 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 73 of 127
- CVE-2025-25968MEDIUMCVSS 6.0EG 6.02025-02-20
DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and explo…
- CVE-2025-26010CRITICALCVSS 9.8EG 9.82025-03-26
Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.
- CVE-2025-2606MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/soulwinning_crud.php. The manipulation of …
- CVE-2025-26062CRITICALCVSS 9.8EG 9.82025-07-31
An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the current settings.
- CVE-2025-2607MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability was found in phplaozhang LzCMS-LaoZhangBoKeXiTong up to 1.1.4. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/upload/upimage.html of the component HTTP POST Request Ha…
- CVE-2025-26138MEDIUMCVSS 6.5EG 6.52025-03-18
Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are accessible via a predictable numerical ID parameter, allowing unauthorized users to increment…
- CVE-2025-26424MEDIUMCVSS 4.0EG 4.02025-09-04
In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne…
- CVE-2025-26606CRITICALCVSS 9.8EG 9.82025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `informacao_adicional.php` endpoint. This vulnerability could allow an a…
- CVE-2025-26607CRITICALCVSS 9.8EG 9.82025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `documento_excluir.php` endpoint. This vulnerability could allow an atta…
- CVE-2025-26608CRITICALCVSS 9.8EG 9.82025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `dependente_docdependente.php` endpoint. This vulnerability could allow …
- CVE-2025-26609CRITICALCVSS 9.8EG 9.82025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `familiar_docfamiliar.php` endpoint. This vulnerability could allow an a…
- CVE-2025-26611CRITICALCVSS 9.8EG 9.82025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `remover_produto.php` endpoint. This vulnerability could allow an attack…
- CVE-2025-26613CRITICALCVSS 9.8EG 9.82025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the WeGIA application, `gerenciar_backup.php` endpoint. This vulnerability could allow …
- CVE-2025-26615CRITICALCVSS 10.0EG 10.02025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `examples.php` endpoint. This vulnerability could allow an attacker to …
- CVE-2025-26616HIGHCVSS 7.5EG 7.52025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `exportar_dump.php` endpoint. This vulnerability could allow an attacke…
- CVE-2025-26617CRITICALCVSS 9.8EG 9.82025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an att…
- CVE-2025-26645HIGHCVSS 8.8EG 8.82025-03-11
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2025-26678HIGHCVSS 8.4EG 8.42025-04-08
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
- CVE-2025-2671MEDIUMCVSS 6.3EG 6.32025-03-23
A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affects the function base64image of the file /app/controller/Upload.php. The manipulation of the argument data lead…
- CVE-2025-2686MEDIUMCVSS 6.5EG 6.52025-03-24
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. Affected by this vulnerability is the function doFilter of the file …
- CVE-2025-2687MEDIUMCVSS 6.3EG 6.32025-03-24
A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is poss…
- CVE-2025-2688MEDIUMCVSS 4.3EG 4.32025-03-24
A vulnerability classified as problematic was found in TOTOLINK A3000RU up to 5.9c.5185. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ExportSyslog.sh of the component Syslog Configuration File Handler. Th…
- CVE-2025-2702MEDIUMCVSS 6.3EG 6.32025-03-24
A vulnerability, which was classified as critical, has been found in Softwin WMX3 3.1. This issue affects the function ImageAdd of the file /ImageAdd.ashx. The manipulation of the argument File leads to unrestricted upload. The attack may …
- CVE-2025-2705HIGHCVSS 7.3EG 7.32025-03-24
A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument File leads to unrestricted upload. It is possible…
- CVE-2025-2706MEDIUMCVSS 6.3EG 6.32025-03-24
A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. The manipulation of the argument File leads to unrestricted uplo…
- CVE-2025-27062HIGHCVSS 7.8EG 7.82025-08-06
Memory corruption while handling client exceptions, allowing unauthorized channel access.
- CVE-2025-27093MEDIUMCVSS 6.3EG 6.32025-10-28
Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to co…
- CVE-2025-27134HIGHCVSS 8.8EG 8.82025-04-30
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version 3.3.3, a privilege escalation vulnerability exists in the Joplin server, allowing non-admi…
- CVE-2025-27140CRITICALCVSS 9.8EG 9.82025-02-24
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This vulnerability could allow an attacker to exec…
- CVE-2025-27153MEDIUMCVSS 6.5EG 6.52025-07-01
Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This can lead to data exposure and workflow disruptions. This issue has been patched in versio…
- CVE-2025-27190MEDIUMCVSS 5.3EG 5.32025-04-08
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabilit…
- CVE-2025-27191MEDIUMCVSS 5.3EG 5.32025-04-08
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabilit…
- CVE-2025-27206MEDIUMCVSS 5.3EG 5.32025-06-10
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to …
- CVE-2025-27207MEDIUMCVSS 6.5EG 6.52025-06-10
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerab…
- CVE-2025-27215HIGHCVSS 8.1EG 8.12025-08-21
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to the system. Affected Products: UniFi Connect Display Cast (Version 1.…
- CVE-2025-27238LOWCVSS 3.5EG 3.52025-09-12
Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
- CVE-2025-27258CRITICALCVSS 9.8EG 9.82025-10-13
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
- CVE-2025-27646CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Edit User Account Exposure V-2024-001.
- CVE-2025-27649CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.893 Application 20.0.2140 allows Incorrect Access Control: PHP V-2023-016.
- CVE-2025-27689HIGHCVSS 7.8EG 7.82025-06-12
Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
- CVE-2025-27702MEDIUMCVSS 4.9EG 4.92025-05-28
CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those p…
- CVE-2025-27724CRITICALCVSS 9.3EG 9.32025-07-28
A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated capabilities. An attacker can upload a malicious file to trigger thi…
- CVE-2025-27738MEDIUMCVSS 6.5EG 6.52025-04-08
Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.
- CVE-2025-27744HIGHCVSS 7.8EG 7.82025-04-08
Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.
- CVE-2025-27919HIGHCVSS 8.2EG 8.22025-11-06
An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from …
- CVE-2025-28041HIGHCVSS 8.6EG 8.62025-08-20
Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication.
- CVE-2025-28104CRITICALCVSS 9.1EG 9.12025-04-21
Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
- CVE-2025-28201MEDIUMCVSS 6.8EG 6.82025-05-09
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.
- CVE-2025-28229CRITICALCVSS 9.8EG 9.82025-04-18
Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.
- CVE-2025-28231CRITICALCVSS 9.1EG 9.12025-04-18
Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →