CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,304 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 66 of 127
- CVE-2025-0346MEDIUMCVSS 4.7EG 4.72025-01-09
A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php of the component Publish News Page. The manipulation of the argum…
- CVE-2025-0399MEDIUMCVSS 4.7EG 4.72025-01-12
A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects the function UploadController of the file src/main/java/com/siro/mall/controller/common/uploadController.java. The manipu…
- CVE-2025-0402MEDIUMCVSS 6.3EG 6.32025-01-13
A vulnerability classified as critical was found in 1902756969 reggie 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/itheima/reggie/controller/CommonController.java. The manipulation of the argumen…
- CVE-2025-0403MEDIUMCVSS 5.3EG 5.32025-01-13
A vulnerability, which was classified as problematic, has been found in 1902756969 reggie 1.0. Affected by this issue is some unknown functionality of the file /user/sendMsg of the component Phone Number Validation Handler. The manipulatio…
- CVE-2025-0460HIGHCVSS 7.3EG 7.32025-01-14
A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads …
- CVE-2025-0463MEDIUMCVSS 6.3EG 6.32025-01-14
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function of the file /crm/weixinmp/index.php?userid=123&module=Users&usid=1&action…
- CVE-2025-0481MEDIUMCVSS 5.3EG 5.32025-01-15
A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the file /dllog.cgi of the component HTTP POST Request Handler. The manipulation leads to information disclosure. It is pos…
- CVE-2025-0582MEDIUMCVSS 4.7EG 4.72025-01-20
A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability affects unknown code of the file /add-pig.php. The manipulation of the argument pigphoto leads to unrestricted upload. Th…
- CVE-2025-0650HIGHCVSS 8.1EG 8.12025-01-23
A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any…
- CVE-2025-0691MEDIUMCVSS 5.0EG 5.02025-06-05
Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permission" permission by bypassing the client side validation.
- CVE-2025-0702MEDIUMCVSS 6.3EG 6.32025-01-24
A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This vulnerability affects unknown code of the file src/main/java/io/github/controller/SysFileController.java. The manip…
- CVE-2025-0722MEDIUMCVSS 4.7EG 4.72025-01-27
A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image Handler. The manipulation of the argument image leads to u…
- CVE-2025-0739HIGHCVSS 8.6EG 8.62025-01-30
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscription's information of others users by changing the "SUSCBRIPTION_ID" param of the endpoin…
- CVE-2025-0740HIGHCVSS 8.6EG 8.62025-01-30
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing the “CHAT_ID” of the endpoint "/embeda…
- CVE-2025-0741MEDIUMCVSS 5.8EG 5.82025-01-30
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embed…
- CVE-2025-0742MEDIUMCVSS 5.8EG 5.82025-01-30
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files stored by others users by changing the "FILE_ID" of the endpoint "/embedai/files/show/<FI…
- CVE-2025-0743MEDIUMCVSS 5.3EG 5.32025-01-30
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by…
- CVE-2025-0744HIGHCVSS 7.5EG 7.52025-01-30
an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST request changing the parameters of the "/dem…
- CVE-2025-0745HIGHCVSS 7.5EG 7.52025-01-30
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the database by requesting the "/embedai/app/uploads/database/<SQL_FILE>" endpoi…
- CVE-2025-0783MEDIUMCVSS 6.3EG 6.32025-01-28
A vulnerability, which was classified as problematic, was found in pankajindevops scale up to 20241113. This affects an unknown part of the component API Endpoint. The manipulation leads to improper access controls. It is possible to initi…
- CVE-2025-0802HIGHCVSS 7.3EG 7.32025-01-29
A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/View_user.php of the component Administrative Endpoint. T…
- CVE-2025-0968MEDIUMCVSS 5.3EG 5.32025-02-19
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it pos…
- CVE-2025-0980MEDIUMCVSS 6.4EG 6.42026-01-07
Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. When exploited, an invalid validation allows JSON RPC access without providing valid authentication credentials.
- CVE-2025-10013MEDIUMCVSS 6.3EG 6.32025-09-05
A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao-para-o-seb. Performing manipulation results in improper access controls. The attack is possible to be carried out remo…
- CVE-2025-10070MEDIUMCVSS 6.3EG 6.32025-09-07
A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /enturmacao-em-lote/. This manipulation causes improper access controls. The attack is possible to be carried out remotely. The exploit has b…
- CVE-2025-10071MEDIUMCVSS 6.3EG 6.32025-09-07
A vulnerability has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /cancelar-enturmacao-em-lote/. Such manipulation leads to improper access controls. The attack may be performed from remo…
- CVE-2025-10072MEDIUMCVSS 6.3EG 6.32025-09-07
A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing manipulation results in improper access controls. It is possible to initiate …
- CVE-2025-10081MEDIUMCVSS 4.7EG 4.72025-09-08
A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation of the argument website_image causes unrestricted upload. Remote exploitation of the atta…
- CVE-2025-10083MEDIUMCVSS 6.3EG 6.32025-09-08
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/profile.php. Executing manipulation can lead to unrestricted upload. The attack …
- CVE-2025-10085MEDIUMCVSS 6.3EG 6.32025-09-08
A security flaw has been discovered in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file manage_website.php. The manipulation results in unrestricted upload. It is possible to launch t…
- CVE-2025-10093MEDIUMCVSS 5.3EG 5.32025-09-08
A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php of the component Device Configuration Handler. Such manipulation leads to information dis…
- CVE-2025-10116HIGHCVSS 7.3EG 7.32025-09-09
A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit is …
- CVE-2025-10201HIGHCVSS 8.8EG 8.82025-09-10
Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-10247MEDIUMCVSS 6.3EG 6.32025-09-11
A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of the component Filter Handler. Such manipulation leads to improper access controls. The attack can be executed remotely.…
- CVE-2025-10321MEDIUMCVSS 5.3EG 5.32025-09-12
A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. The attack can be executed remotely. The exploit has been publis…
- CVE-2025-10371HIGHCVSS 7.3EG 7.32025-09-13
A security flaw has been discovered in eCharge Hardy Barth Salia PLCC up to 2.3.81. This issue affects some unknown processing of the file /api.php. The manipulation of the argument setrfidlist results in unrestricted upload. The attack ma…
- CVE-2025-10398MEDIUMCVSS 6.3EG 6.32025-09-14
A security flaw has been discovered in fcba_zzm ics-park Smart Park Management System 2.0. This vulnerability affects unknown code of the file FileUploadUtils.java. The manipulation of the argument File results in unrestricted upload. The …
- CVE-2025-10424HIGHCVSS 7.3EG 7.32025-09-15
A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The affected element is an unknown function of the file /admin/controller/faculty_controller.php. This manipulation of the a…
- CVE-2025-10425HIGHCVSS 7.3EG 7.32025-09-15
A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown function of the file /admin/controller/student_controller.php. Such manipulation of the a…
- CVE-2025-10427MEDIUMCVSS 6.3EG 6.32025-09-15
A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. This impacts an unknown function of the file /admin/operation/user.php. Executing manipulation of the argument website_image can lead to unrestricted up…
- CVE-2025-10428MEDIUMCVSS 6.3EG 6.32025-09-15
A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/seo_setting.php of the component Setting Handler. The manipulation of the argument websit…
- CVE-2025-10447HIGHCVSS 7.3EG 7.32025-09-15
A vulnerability was detected in Campcodes Online Job Finder System 1.0. The impacted element is an unknown function of the file /eris/applicationform.php. The manipulation of the argument picture results in unrestricted upload. It is possi…
- CVE-2025-10480MEDIUMCVSS 6.3EG 6.32025-09-15
A weakness has been identified in SourceCodester Online Student File Management System 1.0. This affects an unknown function of the file /save_file.php. Executing manipulation can lead to unrestricted upload. The attack may be launched rem…
- CVE-2025-10491HIGHCVSS 7.8EG 7.82025-09-15
The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking. This issue affects MongoDB Server v6.0 version prio…
- CVE-2025-10600HIGHCVSS 7.3EG 7.32025-09-17
A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulation of the argument img causes unrestricted upload. It is possible to initiate the attack re…
- CVE-2025-10607MEDIUMCVSS 4.3EG 4.32025-09-17
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi. Such manipulation leads to information disclosure. The attack can be executed remotely. …
- CVE-2025-10608MEDIUMCVSS 6.3EG 6.32025-09-17
A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Performing manipulation results in improper access controls. The attack is possible to be carried…
- CVE-2025-10615MEDIUMCVSS 6.3EG 6.32025-09-17
A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit is pu…
- CVE-2025-10616MEDIUMCVSS 6.3EG 6.32025-09-17
A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has…
- CVE-2025-10669MEDIUMCVSS 6.3EG 6.32025-09-18
A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component Playlist Upload Handler. Performing manipulation results in unrestricted upload. It is possible to initiate the attack…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →