CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,304 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 68 of 127
- CVE-2025-12276MEDIUMCVSS 4.3EG 4.32025-10-27
A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation results in information disclosure. The attack …
- CVE-2025-12291MEDIUMCVSS 4.7EG 4.72025-10-27
A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an unknown part of the file /admin/index.php?add_product of the component Add Product Page. The manipulation results in unr…
- CVE-2025-12297MEDIUMCVSS 4.3EG 4.32025-10-27
A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.java. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now publi…
- CVE-2025-12301HIGHCVSS 7.3EG 7.32025-10-27
A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct.php. Such manipulation of the argument photo leads to unrestricted upload. The attack can…
- CVE-2025-12331MEDIUMCVSS 4.7EG 4.72025-10-27
A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made…
- CVE-2025-12344MEDIUMCVSS 6.3EG 6.32025-10-28
A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /service/NCloudGatewayServlet of the component Request Header Handler. Such manipulation of the argument ts/sign leads t…
- CVE-2025-12346MEDIUMCVSS 6.3EG 6.32025-10-28
A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_post/uploads-require-maxsite.php of the component HTTP Header Handler. Performing manipulatio…
- CVE-2025-12347MEDIUMCVSS 6.3EG 6.32025-10-28
A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files/save-file-ajax.php. Executing manipulation of the argument file_path/content can lead to …
- CVE-2025-12378HIGHCVSS 7.3EG 7.32025-10-28
A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addproduct.php. Performing manipulation of the argument photo results in unrestricted upload. The…
- CVE-2025-12480CRITICALCVSS 9.1EG 9.1⚠ KEV2025-11-10
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
- CVE-2025-1259HIGHCVSS 7.7EG 7.72025-03-04
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available
- CVE-2025-12593MEDIUMCVSS 4.7EG 4.72025-11-02
A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /admin/edit_room.php of the component Photo Handler. The manipulation leads to unrestricted…
- CVE-2025-1260CRITICALCVSS 9.1EG 9.12025-03-04
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.
- CVE-2025-12808MEDIUMCVSS 6.5EG 6.52025-11-06
Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure. This issue affects the following versions : * …
- CVE-2025-12862MEDIUMCVSS 6.3EG 6.32025-11-07
A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted u…
- CVE-2025-12884MEDIUMCVSS 4.3EG 4.32026-02-19
The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action …
- CVE-2025-13061MEDIUMCVSS 6.3EG 6.32025-11-12
A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Performing manipulation results in unrestricted upload. The attack is possible to be carried…
- CVE-2025-13185MEDIUMCVSS 4.7EG 4.72025-11-14
A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. The manipulation of the argument profile_image/banner_image results in unrestricted upload…
- CVE-2025-13198MEDIUMCVSS 4.7EG 4.72025-11-15
A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the argument File leads to unrestricted upload. Remote exploitation of the…
- CVE-2025-13238MEDIUMCVSS 6.3EG 6.32025-11-16
A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit Profile Page. This manipulation causes unrestricted upload…
- CVE-2025-13249MEDIUMCVSS 6.3EG 6.32025-11-16
A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTemplate=false of the component OfficeServer Interface. Such manipulation of the argument FileD…
- CVE-2025-13250MEDIUMCVSS 6.3EG 6.32025-11-16
A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job Handler. Performing manipulation results in improper access controls. The attack may be i…
- CVE-2025-13275MEDIUMCVSS 4.7EG 4.72025-11-17
A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This affects an unknown part of the file /admin/about.php. The manipulation leads to unrestricted upload. It is po…
- CVE-2025-13411MEDIUMCVSS 4.7EG 4.72025-11-19
A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipulation of the argument product_image resul…
- CVE-2025-13423MEDIUMCVSS 4.7EG 4.72025-11-20
A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lead to unrestricted u…
- CVE-2025-13443MEDIUMCVSS 5.4EG 5.42025-11-20
A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote expl…
- CVE-2025-13544MEDIUMCVSS 6.3EG 6.32025-11-23
A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is …
- CVE-2025-1355HIGHCVSS 7.3EG 7.32025-02-16
A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signup.php of the component Add Picture. The manipulation leads to un…
- CVE-2025-13573MEDIUMCVSS 6.3EG 6.32025-11-24
A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_book.php. The manipulation of the argument image results in unrestricted upload. The attac…
- CVE-2025-13574MEDIUMCVSS 4.7EG 4.72025-11-24
A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The a…
- CVE-2025-13785MEDIUMCVSS 4.3EG 4.32025-11-30
A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the file /user/profile of the component Image Handler. Such manipulation leads to information …
- CVE-2025-13804MEDIUMCVSS 4.3EG 4.32025-12-01
A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/Eth…
- CVE-2025-13815MEDIUMCVSS 6.3EG 6.32025-12-01
A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initiate…
- CVE-2025-1390MEDIUMCVSS 6.1EG 6.12025-02-18
The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users b…
- CVE-2025-1391MEDIUMCVSS 5.4EG 5.42025-02-17
A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leadin…
- CVE-2025-13949MEDIUMCVSS 6.3EG 6.32025-12-03
A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.go. The manipulation of the argument File leads to unrestricted upload. The attack may be …
- CVE-2025-14052MEDIUMCVSS 6.3EG 6.32025-12-05
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the argument memberId leads to improper acces…
- CVE-2025-14082LOWCVSS 2.7EG 2.72025-12-10
A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint.
- CVE-2025-14083LOWCVSS 2.7EG 2.72026-01-21
A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.
- CVE-2025-14086MEDIUMCVSS 6.3EG 6.32025-12-05
A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipulation of the argument openid results in improper access controls. The attack can be execut…
- CVE-2025-14095MEDIUMCVSS 6.8EG 6.82025-12-17
A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user with physical access to the analyzer, the possibility to gain unauthorized access to funct…
- CVE-2025-14195MEDIUMCVSS 6.3EG 6.32025-12-07
A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/add_file_query.php. The manipulation of the argument per_file results in unrestricted uploa…
- CVE-2025-14197MEDIUMCVSS 5.3EG 5.32025-12-07
A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/resources/f96956469e7be39d of the component Web Administration Module. Such manipulation …
- CVE-2025-14198MEDIUMCVSS 5.3EG 5.32025-12-07
A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientreport/download?key=dummytoken of the component Web Administration Module. Performing manipulation results in in…
- CVE-2025-14199MEDIUMCVSS 6.3EG 6.32025-12-07
A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text.txt?override=false of the component Web Administration Module. Executing manipulation…
- CVE-2025-14219MEDIUMCVSS 4.7EG 4.72025-12-08
A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_running.php. Executing a manipulation of the argument product_image can lead to unres…
- CVE-2025-14286MEDIUMCVSS 5.3EG 5.32025-12-09
A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/DownloadCfg.jpg of the component Configuration File Handler. This manipulation causes informatio…
- CVE-2025-14338HIGHCVSS 8.5EG 8.52026-01-14
Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same issues as in CVE-2025-66005.
- CVE-2025-14522MEDIUMCVSS 6.3EG 6.32025-12-11
A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /Public/Kindeditor/php/upload_json.php. Performing manipulation of the argument imgFile res…
- CVE-2025-14528MEDIUMCVSS 5.3EG 5.32025-12-11
A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosure.…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →