CWE-284: Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

1,308
Total CVEs
216
Critical
556
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
123
2025
669
2024
305
2023
121
2022
36

Top Affected Vendors

1 Microsoft 84
2 Apple 79
3 Oracle 57
4 Intel 32
5 Cisco 22
6 Adobe 21
7 Dell 19
8 Fabian 17
9 Mattermost 12
10 Campcodes 11

All Improper Access Control CVEs (1,308)

CVE-2024-20952
7.4

This Java security vulnerability allows attackers to bypass sandbox protections in client-side Java deployments. It affects Java SE, GraalVM for JDK, ...

Jan 16, 2024
CVE-2023-21901
7.4

This vulnerability in Oracle Financial Services Analytical Applications Infrastructure allows authenticated attackers with low privileges to perform u...

Jan 16, 2024
CVE-2024-21589
7.4

An unauthenticated attacker can access sensitive reports in Juniper Networks Paragon Active Assurance Control Center without logging in, potentially e...

Jan 12, 2024
CVE-2021-21964
7.4

A denial of service vulnerability in Sealevel Systems SeaConnect 370W's Modbus configuration allows attackers to crash the device by sending specially...

Feb 4, 2022
CVE-2021-0232
7.4

An authentication bypass vulnerability in Juniper Networks Paragon Active Assurance Control Center allows attackers with specific deployment informati...

Apr 22, 2021
CVE-2026-2164
7.3

CVE-2026-2164 is an unrestricted file upload vulnerability in detronetdip E-commerce 1.0.0 that allows attackers to upload malicious files to the serv...

Feb 8, 2026
CVE-2026-2133
7.3

CVE-2026-2133 is an unrestricted file upload vulnerability in code-projects Online Music Site 1.0 that allows attackers to upload malicious files via ...

Feb 8, 2026
CVE-2025-15503
7.3

CVE-2025-15503 is an unrestricted file upload vulnerability in Sangfor Operation and Maintenance Management System that allows remote attackers to upl...

Jan 10, 2026
CVE-2026-0643
7.3

This vulnerability allows remote attackers to upload arbitrary files through the signup component in House Rental and Property Listing 1.0. Attackers ...

Jan 7, 2026
CVE-2025-15426
7.3

This vulnerability in jackying H-ui.admin allows attackers to upload arbitrary files without restrictions via the /lib/webuploader/0.1.5/server/previe...

Jan 2, 2026
CVE-2025-15109
7.3

This vulnerability allows remote attackers to upload arbitrary files to jackq XCMS systems due to insufficient validation in the upload.php component....

Dec 27, 2025
CVE-2025-14583
7.3

This vulnerability in campcodes Online Student Enrollment System 1.0 allows remote attackers to upload arbitrary files via the photo parameter in /adm...

Dec 12, 2025
CVE-2025-12301
7.3

This vulnerability allows remote attackers to upload arbitrary files to the Simple Food Ordering System 1.0 via the photo parameter in /editproduct.ph...

Oct 27, 2025
CVE-2025-59273
7.3

An improper access control vulnerability in Azure Event Grid allows unauthorized attackers to elevate privileges over a network. This affects Azure Ev...

Oct 23, 2025
CVE-2025-55240
7.3

This vulnerability allows an authorized attacker with local access to a system running Visual Studio to elevate their privileges beyond what they shou...

Oct 14, 2025
CVE-2025-11659
7.3

This vulnerability allows remote attackers to upload arbitrary files to the ProjectsAndPrograms School Management System via the /assets/uploadNotes.p...

Oct 13, 2025
CVE-2025-11660
7.3

This vulnerability allows remote attackers to upload arbitrary files to the ProjectsAndPrograms School Management System via the /assets/uploadSllyabu...

Oct 13, 2025
CVE-2025-11657
7.3

This vulnerability allows attackers to upload arbitrary files to the ProjectsAndPrograms School Management System via the /assets/createNotice.php end...

Oct 13, 2025
CVE-2025-11656
7.3

CVE-2025-11656 is an unrestricted file upload vulnerability in ProjectsAndPrograms School Management System that allows attackers to upload malicious ...

Oct 13, 2025
CVE-2025-45095
7.3

Lavasoft Web Companion (Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 have an unquoted service path vulnerability in DCIService.exe. ...

Oct 9, 2025
CVE-2025-11347
7.3

This vulnerability allows unauthenticated attackers to upload arbitrary files to Student Crud Operation systems, leading to remote code execution. It ...

Oct 7, 2025
CVE-2025-11318
7.3

This vulnerability allows remote attackers to upload arbitrary files to Tipray Data Leakage Prevention System 1.0 via the uploadWxFile.do endpoint. At...

Oct 6, 2025
CVE-2025-10447
7.3

Campcodes Online Job Finder System 1.0 has an unrestricted file upload vulnerability in the picture upload function of /eris/applicationform.php. This...

Sep 15, 2025
CVE-2025-10424
7.3

This vulnerability allows remote attackers to upload arbitrary files to the 1000projects Online Student Project Report Submission and Evaluation Syste...

Sep 15, 2025
CVE-2025-10371
7.3

This vulnerability allows remote attackers to perform unrestricted file uploads via the /api.php endpoint in eCharge Hardy Barth Salia PLCC systems. A...

Sep 13, 2025
CVE-2025-54116
7.3

This vulnerability allows an authorized attacker with local access to Windows MultiPoint Services to elevate privileges beyond their intended level. I...

Sep 9, 2025
CVE-2025-10116
7.3

This vulnerability allows remote attackers to upload arbitrary files to SiempreCMS installations via the /docs/admin/file_upload.php endpoint. This ca...

Sep 9, 2025
CVE-2025-9775
7.3

CVE-2025-9775 is an unrestricted file upload vulnerability in RemoteClinic's staff profile editing functionality. Attackers can upload malicious files...

Sep 1, 2025
CVE-2025-9772
7.3

CVE-2025-9772 is an unrestricted file upload vulnerability in RemoteClinic's /staff/edit.php endpoint that allows attackers to upload malicious files ...

Sep 1, 2025
CVE-2025-9476
7.3

This vulnerability allows remote attackers to upload arbitrary files to SourceCodester Human Resource Information System 1.0 via the /Superadmin_Dashb...

Aug 26, 2025
CVE-2025-55630
7.3

This vulnerability allows attackers to determine valid user accounts on Reolink Smart Doorbell systems by analyzing differences in error messages duri...

Aug 22, 2025
CVE-2025-8798
7.3

This critical vulnerability in oitcode samarium allows unrestricted file uploads via the Create Product Page component. Attackers can remotely exploit...

Aug 10, 2025
CVE-2025-23277
7.3

This vulnerability in NVIDIA Display Driver allows attackers to access memory outside permitted bounds in kernel mode. Successful exploitation could l...

Aug 2, 2025
CVE-2025-29556
7.3

CVE-2025-29556 is an access control bypass vulnerability in ExaGrid EX10 backup appliances that allows authenticated administrators to create or modif...

Jul 31, 2025
CVE-2025-8255
7.3

This critical vulnerability in Exam Form Submission 1.0 allows remote attackers to upload arbitrary files via the /register.php endpoint. Attackers ca...

Jul 28, 2025
CVE-2025-7547
7.3

This critical vulnerability in Campcodes Online Movie Theater Seat Reservation System 1.0 allows remote attackers to upload arbitrary files via the 'c...

Jul 13, 2025
CVE-2025-6843
7.3

CVE-2025-6843 is a critical unrestricted file upload vulnerability in Simple Photo Gallery 1.0 that allows remote attackers to upload arbitrary files ...

Jun 29, 2025
CVE-2025-4923
7.3

This critical vulnerability in SourceCodester Client Database Management System 1.0 allows remote attackers to upload arbitrary files via the /user_de...

May 19, 2025
CVE-2025-20052
7.3

This vulnerability in Intel Graphics software allows authenticated local users to potentially cause denial of service by exploiting improper access co...

May 13, 2025
CVE-2024-45333
7.3

An improper access control vulnerability in Intel Data Center GPU Flex Series drivers for Windows allows authenticated local users to potentially caus...

May 13, 2025
CVE-2025-3566
7.3

This critical vulnerability in veal98 Echo Community System 4.2 allows remote attackers to upload arbitrary files without authentication via the uploa...

Apr 14, 2025
CVE-2025-21425
7.3

This vulnerability allows memory corruption in the HAB (Hardware Abstraction Layer) process due to improper access control. Attackers could potentiall...

Apr 7, 2025
CVE-2025-2705
7.3

This critical vulnerability in Digiwin ERP 5.1 allows remote attackers to upload arbitrary files without restrictions via the DoUpload/DoWebUpload fun...

Mar 24, 2025
CVE-2025-25585
7.3

This vulnerability allows unauthorized attackers to modify administrator passwords in yimioa software due to improper access control in the WebSecurit...

Mar 18, 2025
CVE-2025-2219
7.3

This critical vulnerability in LoveCardsV2 allows unauthenticated attackers to upload arbitrary files to the /api/upload/image endpoint, potentially l...

Mar 12, 2025
CVE-2025-24994
7.3

This vulnerability allows an authenticated attacker on a Windows system to exploit improper access control in the Cross Device Service to gain elevate...

Mar 11, 2025
CVE-2025-24076
7.3

This vulnerability in Windows Cross Device Service allows an authenticated attacker to escalate privileges on a local system. It affects Windows devic...

Mar 11, 2025
CVE-2025-1646
7.3

This critical vulnerability in Lumsoft ERP 8 allows remote attackers to upload arbitrary files via the /Api/TinyMce/UploadAjaxAPI.ashx endpoint due to...

Feb 25, 2025
CVE-2025-1555
7.3

This critical vulnerability in hzmanyun Education and Training System 3.1.1 allows remote attackers to upload arbitrary files without restrictions via...

Feb 21, 2025
CVE-2025-1355
7.3

This critical vulnerability in needyamin Library Card System 1.0 allows attackers to upload arbitrary files to the /signup.php endpoint, potentially l...

Feb 16, 2025

About Improper Access Control (CWE-284)

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Our database tracks 1,308 CVEs classified as CWE-284, with 216 rated critical and 556 rated high severity. The average CVSS score for Improper Access Control vulnerabilities is 7.2.

External reference: View CWE-284 on MITRE CWE →

Monitor Improper Access Control Vulnerabilities

Get alerted when new Improper Access Control CVEs affect your infrastructure.

Start Monitoring Free