CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,304 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 70 of 127
- CVE-2025-20052HIGHCVSS 7.3EG 7.32025-05-13
Improper access control for some Intel(R) Graphics software may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2025-20076MEDIUMCVSS 5.0EG 5.02025-05-13
Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
- CVE-2025-20099MEDIUMCVSS 6.7EG 6.72025-08-12
Improper access control for some Intel(R) Rapid Storage Technology installation software may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-20100HIGHCVSS 7.5EG 7.52025-05-13
Improper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2025-20130MEDIUMCVSS 4.9EG 4.92025-06-04
A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. Th…
- CVE-2025-20131MEDIUMCVSS 4.9EG 4.92025-08-20
A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of t…
- CVE-2025-20137MEDIUMCVSS 4.7EG 4.72025-05-07
A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, remote attacker to bypass a configured ACL…
- CVE-2025-20144MEDIUMCVSS 4.0EG 4.02025-03-12
A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect handling of p…
- CVE-2025-20153MEDIUMCVSS 5.8EG 5.82025-02-19
A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.…
- CVE-2025-20159MEDIUMCVSS 5.3EG 5.32025-09-10
A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass configured ACLs for the SSH, NetConf, and gRPC features. This vu…
- CVE-2025-20190MEDIUMCVSS 6.5EG 6.52025-05-07
A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device. This vulnerability is due…
- CVE-2025-20219MEDIUMCVSS 5.3EG 5.32025-08-14
A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticate…
- CVE-2025-20223MEDIUMCVSS 4.7EG 4.72025-05-07
A vulnerability in Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to read and modify data in a repository that belongs to an internal service of an affected device. This vulnerability is …
- CVE-2025-20229HIGHCVSS 8.0EG 8.02025-03-26
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles…
- CVE-2025-20230MEDIUMCVSS 4.3EG 4.32025-03-26
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Spl…
- CVE-2025-20242MEDIUMCVSS 6.5EG 6.52025-05-21
A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper…
- CVE-2025-2031MEDIUMCVSS 6.3EG 6.32025-03-06
A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile of the file /dev-api/cms/file/upload. The manipulation of the argument file leads to unrestricted upload. It is possible…
- CVE-2025-20316MEDIUMCVSS 5.3EG 5.32025-09-24
A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL on an affected device. T…
- CVE-2025-20323MEDIUMCVSS 4.3EG 4.32025-07-07
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn off the scheduled search `Bucket Copy Trigger` within the Splunk Archiver applicat…
- CVE-2025-20324MEDIUMCVSS 5.4EG 5.42025-07-07
In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119, a low-privileged user that does not hold the "admin" or "power" Splunk roles could c…
- CVE-2025-20335MEDIUMCVSS 5.3EG 5.32025-09-03
A vulnerability in the directory permissions of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could allow an unauthenticated, remote attacker to write arbitrary files on an affected device. …
- CVE-2025-20339MEDIUMCVSS 5.8EG 5.82025-09-24
A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the improper enforcement…
- CVE-2025-20341HIGHCVSS 8.8EG 8.82025-11-13
A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system. This vulnerability is due to insufficient validation of user-supplied…
- CVE-2025-2035MEDIUMCVSS 6.3EG 6.32025-03-06
A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /customer_register.php. The manipulation of the argument name leads to unrest…
- CVE-2025-20366MEDIUMCVSS 6.5EG 6.52025-10-01
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensi…
- CVE-2025-2089MEDIUMCVSS 5.4EG 5.42025-03-07
A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUserInfo of the file /personal/updateInfo of the component com.siro.mall.controller.mall.User…
- CVE-2025-2090MEDIUMCVSS 4.7EG 4.72025-03-07
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php of the component Sub Admin Handler. The manipulat…
- CVE-2025-21031MEDIUMCVSS 6.8EG 6.82025-09-03
Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.
- CVE-2025-21105MEDIUMCVSS 6.6EG 6.62025-02-20
Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could potentially exploit this vulnerability by running the specific binary and perform any administ…
- CVE-2025-2115MEDIUMCVSS 6.3EG 6.32025-03-09
A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRequest of the file /AcceptZip.ashx. The manipulation of the argument file leads to unrestri…
- CVE-2025-21173HIGHCVSS 7.3EG 7.32025-01-14
.NET Elevation of Privilege Vulnerability
- CVE-2025-21185MEDIUMCVSS 6.5EG 6.52025-01-17
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2025-21197MEDIUMCVSS 6.5EG 6.52025-04-08
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.
- CVE-2025-21202MEDIUMCVSS 6.1EG 6.12025-01-14
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
- CVE-2025-2121MEDIUMCVSS 6.3EG 6.32025-03-09
A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the component File Storage. The manipulation leads to improper access controls. The attack can only …
- CVE-2025-21213MEDIUMCVSS 4.6EG 4.62025-01-14
Secure Boot Security Feature Bypass Vulnerability
- CVE-2025-21293HIGHCVSS 8.8EG 8.82025-01-14
Active Directory Domain Services Elevation of Privilege Vulnerability
- CVE-2025-21301MEDIUMCVSS 6.5EG 6.52025-01-14
Windows Geolocation Service Information Disclosure Vulnerability
- CVE-2025-21337LOWCVSS 3.3EG 3.32025-02-11
Windows NTFS Elevation of Privilege Vulnerability
- CVE-2025-21340MEDIUMCVSS 5.5EG 5.52025-01-14
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
- CVE-2025-21359HIGHCVSS 7.8EG 7.82025-02-11
Windows Kernel Security Feature Bypass Vulnerability
- CVE-2025-21380HIGHCVSS 8.8EG 8.82025-01-09
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
- CVE-2025-21405HIGHCVSS 7.3EG 7.32025-01-14
Visual Studio Elevation of Privilege Vulnerability
- CVE-2025-21425HIGHCVSS 7.3EG 7.32025-04-07
Memory corruption may occur due top improper access control in HAB process.
- CVE-2025-21469HIGHCVSS 7.8EG 7.82025-05-06
Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.
- CVE-2025-21470HIGHCVSS 7.8EG 7.82025-05-06
Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.
- CVE-2025-21573MEDIUMCVSS 6.0EG 6.02025-04-15
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Chatbot). Supported versions that are affected are 5.1.0.0.0, 6.1.0.0.0 and 7.0.0.0.0. Difficult …
- CVE-2025-21586MEDIUMCVSS 5.4EG 5.42025-04-15
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with …
- CVE-2025-21587HIGHCVSS 7.4EG 7.42025-04-15
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE:8u441, 8u441-perf, 11.0.26, 17.0.14, 21.0.…
- CVE-2025-21588MEDIUMCVSS 4.9EG 4.92025-04-15
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network acces…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →