CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,305 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 77 of 127
- CVE-2025-36636MEDIUMCVSS 4.3EG 4.32025-10-08
In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
- CVE-2025-3664MEDIUMCVSS 5.3EG 5.32025-04-16
A vulnerability, which was classified as critical, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is…
- CVE-2025-3665MEDIUMCVSS 5.3EG 5.32025-04-16
A vulnerability has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this vulnerability is the function setSmartQosCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access c…
- CVE-2025-3666MEDIUMCVSS 5.3EG 5.32025-04-16
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as critical. Affected by this issue is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. The atta…
- CVE-2025-3667MEDIUMCVSS 5.3EG 5.32025-04-16
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls. It is possib…
- CVE-2025-3668MEDIUMCVSS 5.3EG 5.32025-04-16
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access contro…
- CVE-2025-3674MEDIUMCVSS 5.3EG 5.32025-04-16
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper acc…
- CVE-2025-3675MEDIUMCVSS 5.3EG 5.32025-04-16
A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi. The manipulation leads to improper access controls…
- CVE-2025-36909MEDIUMCVSS 5.3EG 5.32025-09-04
Information disclosure
- CVE-2025-37125HIGHCVSS 7.5EG 7.52025-09-16
A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly
- CVE-2025-37131MEDIUMCVSS 4.9EG 4.92025-09-16
A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sens…
- CVE-2025-37135MEDIUMCVSS 6.5EG 6.52025-10-14
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to d…
- CVE-2025-37136MEDIUMCVSS 6.5EG 6.52025-10-14
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to d…
- CVE-2025-37137MEDIUMCVSS 6.5EG 6.52025-10-14
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to d…
- CVE-2025-37140MEDIUMCVSS 4.9EG 4.92025-10-14
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files throug…
- CVE-2025-37141MEDIUMCVSS 4.9EG 4.92025-10-14
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files throug…
- CVE-2025-37142MEDIUMCVSS 4.9EG 4.92025-10-14
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files throug…
- CVE-2025-37143MEDIUMCVSS 4.9EG 4.92025-10-14
An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated malicious actor to download …
- CVE-2025-37155HIGHCVSS 7.8EG 7.82025-11-18
A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only users. If successfully exploited, this vulnerability could allow an attacker with read-only…
- CVE-2025-3764MEDIUMCVSS 6.3EG 6.32025-04-17
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /edit-product.php. The manipulation of the argument Avatar leads to un…
- CVE-2025-3765MEDIUMCVSS 6.3EG 6.32025-04-17
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file /edit-photo.php. The manipulation of the argument …
- CVE-2025-3768MEDIUMCVSS 5.0EG 5.02025-06-05
Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.
- CVE-2025-3783MEDIUMCVSS 6.3EG 6.32025-04-18
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-product.php. The manipulation of the argument …
- CVE-2025-3790MEDIUMCVSS 5.3EG 5.32025-04-18
A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /druid/index.html of the component Apache Druid Monitoring Console. The manipulation leads to improper access controls. It…
- CVE-2025-3798MEDIUMCVSS 4.7EG 4.72025-04-19
A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminController.php of the component Advertisement Image Handler. The manipulation leads to unrestri…
- CVE-2025-3807MEDIUMCVSS 6.3EG 6.32025-04-19
A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/UploadController.java of the component Endpoint. The manipulatio…
- CVE-2025-3830MEDIUMCVSS 6.3EG 6.32025-04-20
A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUpload of the file src/main/java/com/kuang/controller/QuestionController.java. The manipulatio…
- CVE-2025-39247HIGHCVSS 8.6EG 8.62025-08-29
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.
- CVE-2025-3966MEDIUMCVSS 4.3EG 4.32025-04-27
A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/home?userId=1&homeSelectType=read of the component Browsing History Handler. The ma…
- CVE-2025-3969MEDIUMCVSS 6.3EG 6.32025-04-27
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of…
- CVE-2025-3975MEDIUMCVSS 5.3EG 5.32025-04-27
A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The…
- CVE-2025-3978MEDIUMCVSS 4.3EG 4.32025-04-27
A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/view/default/user_set.htm. The manipulation leads to information disclosure. The at…
- CVE-2025-4006MEDIUMCVSS 4.7EG 4.72025-04-28
A vulnerability classified as critical has been found in youyiio BeyongCms 1.6.0. Affected is an unknown function of the file /admin/theme/Upload.html of the component Document Management Page. The manipulation of the argument File leads t…
- CVE-2025-4036MEDIUMCVSS 6.3EG 6.32025-04-28
A vulnerability was found in 201206030 Novel 3.5.0 and classified as critical. This issue affects the function updateBookChapter of the file src/main/java/io/github/xxyopen/novel/controller/author/AuthorController.java of the component Cha…
- CVE-2025-4051MEDIUMCVSS 6.3EG 6.32025-05-05
Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium sec…
- CVE-2025-4064MEDIUMCVSS 5.3EG 5.32025-04-29
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/viewenquiry.php. The manipulation leads to improper access controls. It is possible…
- CVE-2025-4065HIGHCVSS 7.3EG 7.32025-04-29
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/addadvertisement.php. The manipulation leads to improper access controls. …
- CVE-2025-4066HIGHCVSS 7.3EG 7.32025-04-29
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/addpackage.php. The manipulation leads to improper access controls. The at…
- CVE-2025-4067MEDIUMCVSS 5.3EG 5.32025-04-29
A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admin/viewpackage.php. The manipulation leads to improper access controls. It is possible to l…
- CVE-2025-40939MEDIUMCVSS 4.6EG 4.62025-12-09
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the device to trigger re…
- CVE-2025-4118MEDIUMCVSS 5.3EG 5.32025-04-30
A vulnerability classified as critical has been found in Weitong Mall 1.0.0. This affects an unknown part of the file /historyList of the component Product History Handler. The manipulation of the argument isDelete with the input 1 leads t…
- CVE-2025-4119MEDIUMCVSS 5.3EG 5.32025-04-30
A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the component Product Statistics Handler. The manipulation of the argument isDelete with the input 1…
- CVE-2025-41258HIGHCVSS 8.0EG 8.02026-03-18
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.
- CVE-2025-41737HIGHCVSS 7.5EG 7.52025-11-18
Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.
- CVE-2025-4258MEDIUMCVSS 6.3EG 6.32025-05-05
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youkefu-master\src\main\java\com\ukefu\webim\web\handler\resource\MediaController.java. The ma…
- CVE-2025-4259MEDIUMCVSS 6.3EG 6.32025-05-05
A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File …
- CVE-2025-4269MEDIUMCVSS 6.5EG 6.52025-05-05
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi of the component Log Handler. The manipulation of the argument topicurl with th…
- CVE-2025-4270MEDIUMCVSS 5.3EG 5.32025-05-05
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Config Handler. The manipulation of the argument topicurl wit…
- CVE-2025-4271MEDIUMCVSS 5.3EG 5.32025-05-05
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the i…
- CVE-2025-4281MEDIUMCVSS 4.3EG 4.32025-05-05
A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 7. This affects an unknown part of the file /api/GylOperator/LoadData. The manipulation leads to inf…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →