CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,305 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 84 of 127
- CVE-2025-5649MEDIUMCVSS 6.5EG 6.52025-06-05
A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /admin/core/new_user of the component Register Interface. The manipulation leads to impr…
- CVE-2025-56499MEDIUMCVSS 6.5EG 6.52025-11-18
Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.
- CVE-2025-57130HIGHCVSS 8.8EG 8.82025-11-05
An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By sending a specially crafted HTTP request, a low-privilege user ca…
- CVE-2025-57197MEDIUMCVSS 6.0EG 6.52025-09-29
In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass th…
- CVE-2025-57210HIGHCVSS 7.5EG 7.52025-12-04
Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspecified vectors.
- CVE-2025-57212HIGHCVSS 7.5EG 7.52025-12-04
Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a crafted request.
- CVE-2025-57213HIGHCVSS 7.5EG 7.52025-12-04
Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via a crafted request.
- CVE-2025-57219MEDIUMCVSS 5.3EG 5.32025-08-28
Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components via a crafted request.
- CVE-2025-57247CRITICALCVSS 9.1EG 9.12025-10-06
The BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa7a) contains incorrect access control implementation in whitelist management functions. The setColdWhiteList() and setS…
- CVE-2025-57266CRITICALCVSS 9.8EG 9.82025-09-29
An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint.
- CVE-2025-5728HIGHCVSS 8.8EG 8.82025-06-06
A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code of the file /manage_website.php. The manipulation of the argument website_image leads to u…
- CVE-2025-57428MEDIUMCVSS 6.5EG 6.52025-09-29
Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation com…
- CVE-2025-57438MEDIUMCVSS 6.8EG 6.82025-09-22
The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only after the admin explicitly grants access to a manager-level account. However, a manager-level …
- CVE-2025-57489HIGHCVSS 8.1EG 8.12025-12-01
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.
- CVE-2025-57567CRITICALCVSS 9.1EG 9.12025-10-17
A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overw…
- CVE-2025-57758MEDIUMCVSS 4.3EG 4.32025-08-28
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versi…
- CVE-2025-58055MEDIUMCVSS 4.3EG 4.32025-10-01
Discourse is an open-source community discussion platform. In versions 3.5.0 and below, the Discourse AI suggestion endpoints for topic “Title”, “Category”, and “Tags” allowed authenticated users to extract information about to…
- CVE-2025-58149HIGHCVSS 7.5EG 7.52025-10-31
When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a result a domain can still have access any 64bit memory BAR when such device is no longer assi…
- CVE-2025-58337MEDIUMCVSS 5.4EG 5.42025-11-05
An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that should have been prevented by read-only restrictions. Impact: Bypasses read-only mode;…
- CVE-2025-5840HIGHCVSS 7.3EG 7.32025-06-07
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the argument uploaded_file …
- CVE-2025-58459MEDIUMCVSS 4.3EG 4.32025-09-03
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.
- CVE-2025-58714HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2025-58724HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
- CVE-2025-58726HIGHCVSS 7.5EG 7.52025-10-14
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- CVE-2025-5873MEDIUMCVSS 6.3EG 6.32025-06-09
A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmware.php of the component Web UI. Performing a manipulation of the argument media results in…
- CVE-2025-58751MEDIUMCVSS 5.3EG 5.32025-09-08
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly e…
- CVE-2025-58752MEDIUMCVSS 5.3EG 5.32025-09-08
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server …
- CVE-2025-59199HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
- CVE-2025-59201HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
- CVE-2025-59218CRITICALCVSS 9.6EG 9.62025-10-09
Azure Entra ID Elevation of Privilege Vulnerability
- CVE-2025-59230CRITICALCVSS 7.8EG 9.0⚠ KEV2025-10-14
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- CVE-2025-59253MEDIUMCVSS 5.5EG 5.52025-10-14
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
- CVE-2025-59273HIGHCVSS 7.3EG 7.32025-10-23
Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-59308MEDIUMCVSS 4.7EG 4.72026-04-24
In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, …
- CVE-2025-59333HIGHCVSS 8.1EG 8.12025-09-16
The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement adequate security controls to properly enforce a "read-only" mode. This vulnerability affects…
- CVE-2025-59422LOWCVSS 3.1EG 3.12025-09-25
Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /console/api/apps/<APP_ID>chat-messages?conversation_id=<CONVERSATION_ID>&limit=10 endpoint allows users in the same worksp…
- CVE-2025-59434CRITICALCVSS 9.6EG 9.62025-09-22
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated vulnerability in Flowise Cloud allows any user on the free tier to access sensitive enviro…
- CVE-2025-59494HIGHCVSS 7.8EG 7.82025-10-14
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
- CVE-2025-59500HIGHCVSS 7.7EG 7.72025-10-23
Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
- CVE-2025-59512HIGHCVSS 7.8EG 7.82025-11-11
Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.
- CVE-2025-59517HIGHCVSS 7.8EG 7.82025-12-09
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-5962HIGHCVSS 7.7EG 7.72025-09-22
A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to access and manipulate the chat history of another user on the same system. By abusing inter-process communication calls t…
- CVE-2025-59697HIGHCVSS 7.2EG 7.22025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configuration to start a root shell upon boot of the host…
- CVE-2025-59702HIGHCVSS 7.2EG 7.22025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal components.
- CVE-2025-59703CRITICALCVSS 9.1EG 9.12025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper evidence. To exploit this, the attacker nee…
- CVE-2025-59810MEDIUMCVSS 6.5EG 6.52025-12-09
An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiS…
- CVE-2025-59923LOWCVSS 2.7EG 2.72025-12-09
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker …
- CVE-2025-59932HIGHCVSS 8.6EG 8.62025-09-27
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthori…
- CVE-2025-59943HIGHCVSS 8.1EG 8.12025-10-03
phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Beca…
- CVE-2025-59951CRITICALCVSS 9.1EG 9.12025-10-01
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix versions 1.5.0 and below, due to being configured with an Nginx reverse proxy, causes the b…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →