CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,309 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 76 of 127
- CVE-2025-31212HIGHCVSS 5.5EG 7.32025-05-12
This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. An app may be able to access sensitive user data.
- CVE-2025-31216LOWCVSS 2.4EG 2.42025-11-21
The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to override managed Wi-Fi profiles.
- CVE-2025-3123MEDIUMCVSS 4.7EG 4.72025-04-02
A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleAction of the component Theme Installation/Plugin Installation. The manipulation leads to unres…
- CVE-2025-31232HIGHCVSS 7.1EG 7.12025-05-12
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A sandboxed app may be able to access sensitive user data.
- CVE-2025-31247HIGHCVSS 7.5EG 7.52025-05-12
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An attacker may gain access to protected parts of the file system.
- CVE-2025-31258MEDIUMCVSS 6.5EG 6.52025-05-12
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.
- CVE-2025-31260HIGHCVSS 5.5EG 7.52025-05-12
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.
- CVE-2025-31268MEDIUMCVSS 5.5EG 5.52025-09-15
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protected user data.
- CVE-2025-31269MEDIUMCVSS 5.5EG 5.52025-09-15
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protected user data.
- CVE-2025-31270MEDIUMCVSS 5.5EG 5.52025-09-15
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access protected user data.
- CVE-2025-31484CRITICALCVSS 9.3EG 9.32025-04-02
conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Between 2025-02-10 and 2025-04-01, conda-forge infrastructure used the wrong token for Azure's cf-staging access. This bu…
- CVE-2025-31486MEDIUMCVSS 5.3EG 5.92025-04-03
Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass.…
- CVE-2025-31494LOWCVSS 3.5EG 3.52025-04-15
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. The AutoGPT Platform's WebSocket API transmitted node execution updates to subscribers based o…
- CVE-2025-3169MEDIUMCVSS 5.0EG 5.02025-04-03
A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tool/saveAttachment.php. The manipulation of the argument attachmentFiles leads to unrest…
- CVE-2025-31698HIGHCVSS 7.5EG 7.52025-06-19
ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.config.acl.subjects) to choose which IP addresses to use for the ACL if Apache Traffic Ser…
- CVE-2025-31725MEDIUMCVSS 5.5EG 5.52025-04-02
Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
- CVE-2025-31726MEDIUMCVSS 5.5EG 5.52025-04-02
Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller f…
- CVE-2025-32037LOWCVSS 2.0EG 2.02025-11-11
Improper access control for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow a denial of service. Network adversary with a privileged user combined with a high complexity attack may enable denial of …
- CVE-2025-3236MEDIUMCVSS 5.3EG 5.32025-04-04
A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/VirSerDMZ of the component Web Management Interface. The manipulation leads to improper …
- CVE-2025-3237MEDIUMCVSS 5.3EG 5.32025-04-04
A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/wrlwpsset. The manipulation leads to improper access controls. The attack may be initiat…
- CVE-2025-32376MEDIUMCVSS 4.3EG 4.32025-04-30
Discourse is an open-source discussion platform. Prior to versions 3.4.3 on the stable branch and 3.5.0.beta3 on the beta branch, the users limit for a DM can be bypassed, thus giving the ability to potentially create a DM with every user …
- CVE-2025-3244MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add-admin.php of the component Create U…
- CVE-2025-32470HIGHCVSS 7.5EG 7.52025-04-28
A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.
- CVE-2025-3255MEDIUMCVSS 4.3EG 4.32025-04-04
A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/home. The manipulation of the argument ID leads to improper access cont…
- CVE-2025-3256MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipulation of the argument email leads to improper access controls…
- CVE-2025-32714HIGHCVSS 7.8EG 7.82025-06-10
Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2025-32722MEDIUMCVSS 5.5EG 5.52025-06-10
Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.
- CVE-2025-32726MEDIUMCVSS 6.8EG 6.82025-04-12
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
- CVE-2025-32790MEDIUMCVSS 6.3EG 6.32025-04-18
Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in '/export' should only a…
- CVE-2025-32795MEDIUMCVSS 6.5EG 6.52025-04-18
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control f…
- CVE-2025-32796MEDIUMCVSS 6.5EG 6.52025-04-18
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the API, even though the web UI button for this action is disabl…
- CVE-2025-3298MEDIUMCVSS 4.3EG 4.32025-04-05
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registr…
- CVE-2025-32992HIGHCVSS 8.5EG 8.52025-08-18
Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.
- CVE-2025-3305MEDIUMCVSS 4.3EG 4.32025-04-05
A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerability affects the function addInterceptors of the file MvcConfig.java of the component Borrow Handler. The manipulation…
- CVE-2025-33056HIGHCVSS 7.5EG 7.52025-06-10
Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.
- CVE-2025-33072HIGHCVSS 8.1EG 8.12025-05-08
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
- CVE-2025-33073CRITICALCVSS 8.8EG 9.0⚠ KEV2025-06-10
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
- CVE-2025-3324MEDIUMCVSS 6.3EG 6.32025-04-06
A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown functionality of the file FileRestController.java. The manipulation of the argument File leads …
- CVE-2025-3325MEDIUMCVSS 4.3EG 4.32025-04-06
A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part of the file /core/admin/pwd of the component Admin Password Handler. The manipulation of the argument ID lea…
- CVE-2025-3398MEDIUMCVSS 6.3EG 6.32025-04-08
A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blogserver/src/main/java/org/sang/config/WebSecurityConfig.java. The manipulation leads to im…
- CVE-2025-3410MEDIUMCVSS 6.3EG 6.32025-04-08
A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform/train-platform/src/main/java/top/aias/training/controller/LocalStorageController.java. Th…
- CVE-2025-3518MEDIUMCVSS 4.3EG 4.32025-04-22
It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can be enabled or disabled for specific use cases through configuration. In case the…
- CVE-2025-3558MEDIUMCVSS 6.3EG 6.32025-04-14
A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uploadUserHeadImage. The manipulation of the argument File leads to unrestricted upload. It is…
- CVE-2025-3565MEDIUMCVSS 4.7EG 4.72025-04-14
A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /upload/uploadArticle.do of the component Announcement Management Section. The manipulation …
- CVE-2025-3566HIGHCVSS 7.3EG 7.32025-04-14
A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the function uploadMdPic of the file /discuss/uploadMdPic. The manipulation of the argument editormd-imag…
- CVE-2025-3580MEDIUMCVSS 5.5EG 5.52025-05-23
An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerabili…
- CVE-2025-3585MEDIUMCVSS 6.3EG 6.32025-04-14
A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /upload/ of the component JSP Parser. The manipulation of the argument File leads to unrestricted upload. It is possi…
- CVE-2025-3593MEDIUMCVSS 6.3EG 6.32025-04-14
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerability affects the function Upload of the file /admin/upload/authorImg/. The manipulation of the argument File leads to …
- CVE-2025-36351MEDIUMCVSS 4.3EG 4.32025-09-29
IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
- CVE-2025-3663MEDIUMCVSS 5.3EG 5.32025-04-16
A vulnerability, which was classified as critical, has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. This issue affects the function setWiFiEasyCfg/setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component Password Handl…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →