CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,295 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 52 of 126
- CVE-2024-1308HIGHCVSS 7.5EG 7.52024-04-09
The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'permalink_settings_save' function in all versions up to, and including, 1.0.33. This ma…
- CVE-2024-13102MEDIUMCVSS 5.3EG 5.32025-01-02
A vulnerability classified as critical was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This vulnerability affects unknown code of the file /goform/DDNS of the component DDNS Service. The manipulation leads to improper access control…
- CVE-2024-13103MEDIUMCVSS 5.3EG 5.32025-01-02
A vulnerability, which was classified as critical, has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This issue affects some unknown processing of the file /goform/form2AddVrtsrv.cgi of the component Virtual Service Handler. The …
- CVE-2024-13104MEDIUMCVSS 5.3EG 5.32025-01-02
A vulnerability, which was classified as critical, was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. Affected is an unknown function of the file /goform/form2AdvanceSetup.cgi of the component WiFi Settings Handler. The manipulation le…
- CVE-2024-13105MEDIUMCVSS 5.3EG 5.32025-01-02
A vulnerability has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/form2Dhcpd.cgi of the component DHCPD Setting Handler. Th…
- CVE-2024-13106MEDIUMCVSS 5.3EG 5.32025-01-02
A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation le…
- CVE-2024-13107MEDIUMCVSS 5.3EG 5.32025-01-02
A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been classified as critical. This affects an unknown part of the file /goform/form2LocalAclEditcfg.cgi of the component ACL Handler. The manipulation leads to im…
- CVE-2024-13108MEDIUMCVSS 5.3EG 5.32025-01-02
A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. Th…
- CVE-2024-13110MEDIUMCVSS 4.3EG 4.32025-01-02
A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperCo…
- CVE-2024-13133MEDIUMCVSS 6.3EG 6.32025-01-05
A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStudent of the file src/main/Java/com/wdd/studentmanager/controller/StudentController. java. Th…
- CVE-2024-13134MEDIUMCVSS 6.3EG 6.32025-01-05
A vulnerability, which was classified as critical, was found in ZeroWdd studentmanager 1.0. Affected is the function addTeacher/editTeacher of the file src/main/Java/com/wdd/studentmanager/controller/TeacherController. java. The manipulati…
- CVE-2024-13138MEDIUMCVSS 4.7EG 4.72025-01-05
A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the function upload of the file src/main/java/com/mysiteform/admin/service/ipl/LocalUploadServiceImpl. The manipulation of…
- CVE-2024-13144MEDIUMCVSS 6.3EG 6.32025-01-06
A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/controller/admin/BlogController.java. The manipulation of the arg…
- CVE-2024-13145MEDIUMCVSS 6.3EG 6.32025-01-06
A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/site/blog/my/core/controller/admin/uploadController. java. The manipulation of …
- CVE-2024-13191MEDIUMCVSS 6.3EG 6.32025-01-08
A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/java/com/wdd/myblog/controller/admin/uploadController.java. The manipulation of the argume…
- CVE-2024-13200HIGHCVSS 7.3EG 7.32025-01-09
A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInterceptor.java of the component HTTP POST R…
- CVE-2024-13201MEDIUMCVSS 4.7EG 4.72025-01-09
A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the compon…
- CVE-2024-13210MEDIUMCVSS 4.7EG 4.72025-01-09
A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/A…
- CVE-2024-13211MEDIUMCVSS 6.3EG 6.32025-01-09
A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/main/java/com/house/wym/controller/AdminController.java. The manipulation leads to impro…
- CVE-2024-13212MEDIUMCVSS 6.3EG 6.32025-01-09
A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the argument file …
- CVE-2024-13229MEDIUMCVSS 4.3EG 4.32025-02-13
The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the update_metadata() function in all versions up to, and including, 1.0.235. …
- CVE-2024-13240HIGHCVSS 7.5EG 7.52025-01-09
Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.
- CVE-2024-1343MEDIUMCVSS 4.7EG 4.72024-02-19
A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to read backup files in the directory '%programfiles(x86)% LaborOfficeFree BackUp'.
- CVE-2024-13430MEDIUMCVSS 4.3EG 4.32025-03-12
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.8 via the 'pagelayer_builder_posts_shortcode' function due to insufficient r…
- CVE-2024-13457MEDIUMCVSS 5.3EG 5.32025-01-30
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This m…
- CVE-2024-13514MEDIUMCVSS 4.3EG 4.32025-02-04
The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.5 via the 'bsb-slider' shortcode due to insufficient restrictions on which posts can be includ…
- CVE-2024-13635MEDIUMCVSS 4.3EG 4.32025-03-07
The VK Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.94.2.2 via the page content block. This makes it possible for authenticated attackers, with Contributor-level access…
- CVE-2024-13693MEDIUMCVSS 5.3EG 5.32025-02-25
The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all versions up to, and including, 6.0.9. This makes it possible for unauthenticated attackers to exp…
- CVE-2024-1370MEDIUMCVSS 5.3EG 5.32024-03-13
The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it p…
- CVE-2024-1376MEDIUMCVSS 4.3EG 4.32024-05-24
The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check on the save_bulkdatas function in all versions up to, and including, 5.9.4. This makes it possible for authenticated a…
- CVE-2024-13854MEDIUMCVSS 4.3EG 4.32025-02-19
The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.1 via the naedu_elementor_template shortcode due to missing validation on a user controlled …
- CVE-2024-13855MEDIUMCVSS 4.3EG 4.32025-02-20
The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the pae_global_block shortcode due to missing validation on a user controlled key. This m…
- CVE-2024-1418MEDIUMCVSS 5.3EG 5.32024-04-04
The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST API. This makes it possible for unauthenticated attackers to view protected posts via REST…
- CVE-2024-1439MEDIUMCVSS 6.5EG 6.52024-02-12
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all…
- CVE-2024-1462MEDIUMCVSS 5.3EG 5.32024-03-13
The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles and content when t…
- CVE-2024-1472MEDIUMCVSS 5.3EG 5.32024-02-29
The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.6 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's maintenance mode obtain…
- CVE-2024-1473MEDIUMCVSS 5.3EG 5.32024-03-20
The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes it possible for unauthenticated attackers to obtain post an…
- CVE-2024-1475MEDIUMCVSS 5.3EG 5.32024-02-29
The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the REST API. This makes it possible for unauthenticated attackers to obtain post and pag…
- CVE-2024-1476MEDIUMCVSS 5.3EG 5.32024-02-28
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST API. This makes it possible for unauthenticated attackers to …
- CVE-2024-1478MEDIUMCVSS 5.3EG 5.32024-03-05
The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content vi…
- CVE-2024-1492MEDIUMCVSS 5.3EG 5.32024-02-29
The WPify Woo Czech plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the maybe_send_to_packeta function in all versions up to, and including, 4.0.8. This makes it possible for unauthent…
- CVE-2024-1525MEDIUMCVSS 5.3EG 5.32024-02-22
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP …
- CVE-2024-1584MEDIUMCVSS 5.3EG 5.32024-05-02
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in al…
- CVE-2024-1605MEDIUMCVSS 6.6EG 6.62024-03-18
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malicious libraries, whi…
- CVE-2024-1632HIGHCVSS 8.8EG 8.82024-02-28
Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.
- CVE-2024-1668MEDIUMCVSS 6.5EG 6.52024-03-13
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 7.11.5 via the form entries page. This makes it possible for authenticated attacker…
- CVE-2024-1675HIGHCVSS 8.8EG 8.82024-02-21
Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2024-1678MEDIUMCVSS 5.3EG 5.32024-05-02
The Subway – Private Site Option plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin…
- CVE-2024-1701MEDIUMCVSS 5.3EG 5.32024-02-21
A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. The manipulation leads to improper access controls. …
- CVE-2024-1823MEDIUMCVSS 5.3EG 5.32024-02-23
A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file users.php of the component Backend. The manipulation leads to improper access co…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →