CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,304 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 69 of 127
- CVE-2025-14530MEDIUMCVSS 4.7EG 4.72025-12-11
A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin/property.php. Such manipulation of the argument image leads to unrestricted upload. It is…
- CVE-2025-14582MEDIUMCVSS 4.7EG 4.72025-12-12
A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=user-profile. Performing a manipulation of the argument userphoto results in unrestricted up…
- CVE-2025-14583HIGHCVSS 7.3EG 7.32025-12-12
A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack can be la…
- CVE-2025-14641MEDIUMCVSS 4.7EG 4.72025-12-14
A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the argument image causes unrestricted upload. The attack may be initia…
- CVE-2025-14642MEDIUMCVSS 4.7EG 4.72025-12-14
A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be la…
- CVE-2025-14660MEDIUMCVSS 5.6EG 5.62025-12-14
A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the component Workspace Domain Handler. This manipulation of the argumen…
- CVE-2025-14748MEDIUMCVSS 5.4EG 5.42025-12-16
A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVIF Device Management Service. Executing manipulation of the argument FactoryDefault with th…
- CVE-2025-14749MEDIUMCVSS 6.3EG 6.32025-12-16
A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVIF PTZ Control Interface. The manipulation leads to improper access controls. The attack re…
- CVE-2025-14885MEDIUMCVSS 6.3EG 6.32025-12-18
A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the component Leads Generation Module. Executing manipulation can lead to unrestricted upload. The a…
- CVE-2025-14977HIGHCVSS 8.1EG 8.12026-01-20
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan…
- CVE-2025-15009MEDIUMCVSS 6.3EG 6.32025-12-22
A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/common/upload of the component Filename Handler. Executing manipulation of the argument File …
- CVE-2025-15050MEDIUMCVSS 6.3EG 6.32025-12-24
A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.php. Such manipulation of the argument File leads to unrestricted upload. The attack can be…
- CVE-2025-15082MEDIUMCVSS 5.3EG 5.32025-12-25
A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Management Interface. Performing manipulation of the argument goformId results in information discl…
- CVE-2025-15084LOWCVSS 3.1EG 3.12025-12-25
A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java of the com…
- CVE-2025-15086MEDIUMCVSS 4.3EG 4.32025-12-25
A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. This manipulation cause…
- CVE-2025-15109HIGHCVSS 7.3EG 7.32025-12-27
A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of the file Public/javascripts/admin/plupload-2.1.2/examples/upload.php. This manipulation causes unrestricted upload. It …
- CVE-2025-15110MEDIUMCVSS 4.7EG 4.72025-12-27
A vulnerability has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. Affected is the function Upload of the file Admin/Home/Controller/ProductImageController.class.php of the component Backend. Such manipulation of …
- CVE-2025-15121LOWCVSS 2.4EG 2.42025-12-28
A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys/sysDepartRole/getDeptRoleByUserId. Such manipulation of the argument departId leads to information disclosur…
- CVE-2025-15141LOWCVSS 3.1EG 3.12025-12-28
A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to information disclosure. The attack may be p…
- CVE-2025-15152MEDIUMCVSS 6.3EG 6.32025-12-28
A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability affects the function addProduct of the file src/main/java/com/ms/product/controller/PmsProductController.java. Such mani…
- CVE-2025-15197MEDIUMCVSS 4.7EG 4.72025-12-29
A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results…
- CVE-2025-15199MEDIUMCVSS 6.3EG 6.32025-12-29
A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboard/userprofile.php. The manipulation of the argument image leads to unrestricted upload. Re…
- CVE-2025-15262MEDIUMCVSS 4.7EG 4.72025-12-30
A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/edit.php of the component Site Logo Handler. Performing a manipulation of the argument image results in unrestricted …
- CVE-2025-15360MEDIUMCVSS 4.7EG 4.72025-12-30
A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd/newbee/mall/controller/common/UploadController.java of the component Product Information Edit Page. This manipulation …
- CVE-2025-15404MEDIUMCVSS 8.8EG 6.32026-01-01
A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /save_file.php. The manipulation of the argument File leads to unrestricted upload. The atta…
- CVE-2025-15415MEDIUMCVSS 5.4EG 4.72026-01-01
A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the component XML File Handler. The manipulation of the argument image leads to unrestricted …
- CVE-2025-15423MEDIUMCVSS 8.8EG 6.32026-01-02
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The expl…
- CVE-2025-15426HIGHCVSS 7.3EG 7.32026-01-02
A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/webuploader/0.1.5/server/preview.php. The manipulation leads to unrestricted upload. The attack is possible to be carried…
- CVE-2025-15448MEDIUMCVSS 9.8EG 6.32026-01-05
A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the function Upload of the file src/main/java/com/macro/mall/controller/MinioController.java. The manipulation results in unres…
- CVE-2025-15495MEDIUMCVSS 7.2EG 4.72026-01-09
A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the argument image results in unrestricted upload. The attack can be launched remotely. The e…
- CVE-2025-15503HIGHCVSS 9.8EG 7.32026-01-10
A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argumen…
- CVE-2025-1555HIGHCVSS 7.3EG 7.32025-02-21
A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to unrestricted upload. The attack can be init…
- CVE-2025-15597MEDIUMCVSS 6.3EG 6.32026-03-02
A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is poss…
- CVE-2025-15619LOWCVSS 3.5EG 3.52026-06-23
HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.
- CVE-2025-1568CRITICALCVSS 8.8EG 9.82025-04-16
Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code E…
- CVE-2025-1590MEDIUMCVSS 4.7EG 4.72025-02-23
A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation lead…
- CVE-2025-1593MEDIUMCVSS 4.7EG 4.72025-02-23
A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manip…
- CVE-2025-1595MEDIUMCVSS 5.3EG 5.32025-02-23
A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects unknown code of the file /api/v1/getbaseconfig. The manipulation leads to information disclo…
- CVE-2025-1598MEDIUMCVSS 6.3EG 6.32025-02-24
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/asset_crud.php. The manipulation of the ar…
- CVE-2025-1606MEDIUMCVSS 4.3EG 4.32025-02-24
A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of the file /admin/backup/backups.php. The manipulation leads to information disclosure. The…
- CVE-2025-1646HIGHCVSS 7.3EG 7.32025-02-25
A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx of the component ASPX File Handler. The manipulation of th…
- CVE-2025-1791MEDIUMCVSS 6.3EG 6.32025-03-01
A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data lead…
- CVE-2025-1818MEDIUMCVSS 6.3EG 6.32025-03-02
A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unknown processing of the file src/main/java/com/futvan/z/system/zfile/ZfileAction.upload. The manipulation of the argumen…
- CVE-2025-1834MEDIUMCVSS 6.3EG 6.32025-03-02
A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of the file /resolve. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the a…
- CVE-2025-1835MEDIUMCVSS 6.3EG 6.32025-03-02
A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the function upload of the file /app/controller/Api.php. The manipulation of the argument file leads to unrestricted upload. …
- CVE-2025-1865HIGHCVSS 7.8EG 7.82025-04-04
The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing …
- CVE-2025-1881MEDIUMCVSS 4.3EG 4.32025-03-03
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Video Footage/Live Video Stream. The manipulation leads to im…
- CVE-2025-1882MEDIUMCVSS 5.0EG 5.02025-03-03
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control…
- CVE-2025-1890MEDIUMCVSS 6.3EG 6.32025-03-04
A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of the arg…
- CVE-2025-1941CRITICALCVSS 9.1EG 9.12025-03-04
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firefox 136.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →