CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,305 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 82 of 127
- CVE-2025-51532HIGHCVSS 7.5EG 7.52025-08-06
Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.
- CVE-2025-51539MEDIUMCVSS 5.3EG 5.32025-08-19
EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficient input validation in a script exposed via the web interface. A remote attacker can supply a crafted path parameter to…
- CVE-2025-5162CRITICALCVSS 9.8EG 9.82025-05-26
A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this issue is some unknown functionality of the file /safeEvent/importFile/. The manipulation of the argument logGe…
- CVE-2025-51627MEDIUMCVSS 6.5EG 6.52025-08-05
Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privileges to Administrator.
- CVE-2025-5163MEDIUMCVSS 5.3EG 5.32025-05-26
A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part. The manipulation leads to improper access controls. It is possible to initiate…
- CVE-2025-5171CRITICALCVSS 9.8EG 9.82025-05-26
A vulnerability, which was classified as critical, has been found in llisoft MTA Maita Training System 4.5. This issue affects the function this.fileService.download of the file com\llisoft\controller\OpenController.java. The manipulation …
- CVE-2025-5178CRITICALCVSS 9.8EG 9.82025-05-26
A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected is an unknown function of the file /adm/ajax.php of the component Image File Handler. The manipulation of the argument f…
- CVE-2025-5184HIGHCVSS 7.5EG 7.52025-05-26
A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been classified as problematic. Affected is an unknown function of the component HTTP Response Header Handler. The manipulation leads t…
- CVE-2025-52079HIGHCVSS 8.8EG 8.82025-10-21
The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.
- CVE-2025-52101CRITICALCVSS 9.8EG 9.82025-07-01
linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authentication and retrieve the encrypted "password" and "salt". The password can then be obtained th…
- CVE-2025-52166MEDIUMCVSS 6.5EG 6.52025-07-18
Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate privileges to Administrator and access sensitive components and information.
- CVE-2025-52168MEDIUMCVSS 6.5EG 6.52025-07-18
Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers to access arbitrary files on the system.
- CVE-2025-52289HIGHCVSS 8.0EG 8.02025-07-31
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" …
- CVE-2025-52963MEDIUMCVSS 5.5EG 5.52025-07-11
An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, leading to a Denial-of-Service. Users with "view" permissions can run a s…
- CVE-2025-5299HIGHCVSS 7.3EG 7.32025-05-28
A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_order_customer_update.php. The manipulation of the argument uplo…
- CVE-2025-53003HIGHCVSS 8.2EG 8.22025-07-01
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This has a large internal surface attack area that exposes all sorts of…
- CVE-2025-53028HIGHCVSS 8.2EG 8.22025-07-15
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastruc…
- CVE-2025-53035MEDIUMCVSS 6.5EG 6.52025-10-21
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily …
- CVE-2025-53041MEDIUMCVSS 6.1EG 6.12025-10-21
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network acces…
- CVE-2025-53049HIGHCVSS 8.4EG 8.42025-10-21
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerabilit…
- CVE-2025-53052MEDIUMCVSS 6.1EG 6.12025-10-21
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker w…
- CVE-2025-53057MEDIUMCVSS 5.9EG 5.92025-10-21
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u461, 8u461-perf, 11.0.28, 17.0.16, …
- CVE-2025-53058MEDIUMCVSS 6.1EG 6.12025-10-21
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Application Logging Interfaces). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthentica…
- CVE-2025-53059MEDIUMCVSS 4.9EG 4.92025-10-21
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows high privileged…
- CVE-2025-53060MEDIUMCVSS 6.1EG 6.12025-10-21
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with…
- CVE-2025-53061MEDIUMCVSS 5.5EG 5.52025-10-21
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows high privileged a…
- CVE-2025-53064MEDIUMCVSS 4.3EG 4.32025-10-21
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker w…
- CVE-2025-53071MEDIUMCVSS 4.3EG 4.32025-10-21
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacke…
- CVE-2025-53092MEDIUMCVSS 6.5EG 6.52025-10-16
Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default installations. By default, Strapi reflects the value of the Origin header back in the Acc…
- CVE-2025-53111MEDIUMCVSS 6.5EG 6.52025-07-30
GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized access to some resources. This is fixed in version 10.0.19.
- CVE-2025-53112MEDIUMCVSS 4.3EG 4.32025-07-30
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a lack of permission checks can result in unauthorized removal o…
- CVE-2025-53113LOWCVSS 2.7EG 2.72025-07-30
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65 through 10.0.18, a tech…
- CVE-2025-53360MEDIUMCVSS 4.3EG 4.32025-11-18
pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. In versions prior to 1.0.3, any authenticated user could send requests to agents. …
- CVE-2025-53501HIGHCVSS 8.8EG 8.82025-07-03
Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - Scribunto Extension: from 1.39.X before…
- CVE-2025-53729HIGHCVSS 7.8EG 7.82025-08-12
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
- CVE-2025-53763CRITICALCVSS 9.8EG 9.82025-08-21
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-53791MEDIUMCVSS 4.7EG 4.72025-09-05
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-5382MEDIUMCVSS 6.8EG 6.82025-06-05
Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or change administrators MFA.
- CVE-2025-5387CRITICALCVSS 9.8EG 9.82025-05-31
A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to improper access cont…
- CVE-2025-5389CRITICALCVSS 9.8EG 9.82025-05-31
A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the file /generateController.do?dogenerateOne2Many of the component File Handler. The …
- CVE-2025-5390CRITICALCVSS 9.8EG 9.82025-05-31
A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the component File Handler. The manipulation leads to improper access co…
- CVE-2025-5406HIGHCVSS 8.8EG 8.82025-06-01
A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an unknown function of the file /admin/posts.php?source=add_post. The manipulation of the ar…
- CVE-2025-5409CRITICALCVSS 9.8EG 9.82025-06-01
A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py of the component API Token Handler. The manipulation leads t…
- CVE-2025-54098HIGHCVSS 7.8EG 7.82025-09-09
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-54116HIGHCVSS 7.3EG 7.32025-09-09
Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.
- CVE-2025-5421MEDIUMCVSS 6.3EG 6.32025-06-02
A vulnerability, which was classified as critical, has been found in juzaweb CMS up to 3.4.2. Affected by this issue is some unknown functionality of the file /admin-cp/plugin/editor of the component Plugin Editor Page. The manipulation le…
- CVE-2025-5422MEDIUMCVSS 4.3EG 4.32025-06-02
A vulnerability, which was classified as problematic, was found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/logs/email of the component Email Logs Page. The manipulation leads to improper access controls.…
- CVE-2025-5423MEDIUMCVSS 6.3EG 6.32025-06-02
A vulnerability has been found in juzaweb CMS up to 3.4.2 and classified as critical. This vulnerability affects unknown code of the file /admin-cp/setting/system/general of the component General Setting Page. The manipulation leads to imp…
- CVE-2025-5424MEDIUMCVSS 6.3EG 6.32025-06-02
A vulnerability was found in juzaweb CMS up to 3.4.2 and classified as critical. This issue affects some unknown processing of the file /admin-cp/media of the component Media Page. The manipulation leads to improper access controls. The at…
- CVE-2025-5425MEDIUMCVSS 6.3EG 6.32025-06-02
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as critical. Affected is an unknown function of the file /admin-cp/theme/editor/default of the component Theme Editor Page. The manipulation leads to improper acc…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →