CWE-284: Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

1,310
Total CVEs
216
Critical
557
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
124
2025
669
2024
305
2023
121
2022
36

Top Affected Vendors

1 Microsoft 84
2 Apple 79
3 Oracle 57
4 Intel 32
5 Cisco 22
6 Adobe 21
7 Dell 19
8 Fabian 17
9 Mattermost 12
10 Campcodes 11

All Improper Access Control CVEs (1,310)

CVE-2024-21169
6.5

This vulnerability in Oracle Marketing allows unauthenticated attackers with network access via HTTP to compromise the system. It affects Oracle E-Bus...

Jul 16, 2024
CVE-2024-40547
6.5

PublicCMS v4.0.202302.e contains an arbitrary file content replacement vulnerability in the /admin/cmsTemplate/replace component. This allows authenti...

Jul 12, 2024
CVE-2024-5840
6.5

This CVE describes a Cross-Origin Resource Sharing (CORS) policy bypass vulnerability in Google Chrome that allows attackers to bypass discretionary a...

Jun 11, 2024
CVE-2024-33647
6.5

This vulnerability in Polarion ALM allows authenticated users to bypass project access controls using the Apache Lucene query engine, enabling them to...

May 14, 2024
CVE-2022-24972
6.5

CVE-2022-24972 is an authentication bypass vulnerability in TP-Link TL-WR940N routers that allows network-adjacent attackers to access stored credenti...

Mar 28, 2023
CVE-2025-0980
6.4

Nokia SR Linux has an authentication bypass vulnerability in its JSON-RPC service that allows attackers to access the service without valid credential...

Jan 7, 2026
CVE-2025-50071
6.4

This vulnerability in Oracle Applications Framework allows authenticated attackers with low privileges to perform unauthorized data manipulation (inse...

Jul 15, 2025
CVE-2024-6364
6.4

This vulnerability in Absolute Persistence® allows attackers with physical device access and full network control to execute operating system command...

May 13, 2025
CVE-2026-3748
6.3

CVE-2026-3748 is an unrestricted file upload vulnerability in Bytedesk's SVG file handler that allows attackers to upload malicious files without prop...

Mar 8, 2026
CVE-2026-3187
6.3

This vulnerability allows remote attackers to upload arbitrary files to the sz-boot-parent application via the /api/admin/sys-file/upload API endpoint...

Feb 25, 2026
CVE-2026-2978
6.3

CVE-2026-2978 is an unrestricted file upload vulnerability in FastApiAdmin's Scheduled Task API that allows remote attackers to upload arbitrary files...

Feb 23, 2026
CVE-2026-2183
6.3

This vulnerability allows attackers to upload arbitrary files without restrictions to the Great Developers Certificate Generation System via the /rest...

Feb 8, 2026
CVE-2026-2146
6.3

This vulnerability allows remote attackers to upload arbitrary files without restrictions through the updateAvatar function in guchengwuyue yshopmall....

Feb 8, 2026
CVE-2026-1813
6.3

This vulnerability allows remote attackers to upload arbitrary files to bolo-solo blog systems due to insufficient validation in the FreeMarker templa...

Feb 4, 2026
CVE-2026-1423
6.3

This vulnerability in code-projects Online Examination System 1.0 allows attackers to upload arbitrary files to the /admin_pic.php endpoint, potential...

Jan 26, 2026
CVE-2026-1107
6.3

This vulnerability in EyouCMS allows attackers to perform unrestricted file uploads via manipulation of the 'viewfile' parameter in the Member Avatar ...

Jan 18, 2026
CVE-2026-1061
6.3

This vulnerability allows remote attackers to upload arbitrary files to xiweicheng TMS systems without proper restrictions. Attackers can exploit this...

Jan 17, 2026
CVE-2025-15448
6.3

This vulnerability allows remote attackers to upload arbitrary files to JavaMall applications due to insufficient restrictions in the MinioController ...

Jan 5, 2026
CVE-2026-0577
6.3

CVE-2026-0577 is an unrestricted file upload vulnerability in code-projects Online Product Reservation System 1.0. Attackers can remotely upload malic...

Jan 4, 2026
CVE-2026-0547
6.3

This vulnerability allows remote attackers to upload arbitrary files via the photo parameter in the student registration page of PHPGurukul Online Cou...

Jan 2, 2026
CVE-2025-15199
6.3

This vulnerability allows remote attackers to upload arbitrary files via the image parameter in the userprofile.php file of College Notes Uploading Sy...

Dec 29, 2025
CVE-2025-15152
6.3

This vulnerability allows remote attackers to upload arbitrary files to the moga-mall application by manipulating the objectName parameter in the addP...

Dec 28, 2025
CVE-2025-15050
6.3

This vulnerability allows remote attackers to upload arbitrary files to the Student File Management System 1.0 via the /save_file.php endpoint. Attack...

Dec 24, 2025
CVE-2025-15009
6.3

CVE-2025-15009 is an arbitrary file upload vulnerability in ChestnutCMS up to version 1.5.8 that allows attackers to upload malicious files to the ser...

Dec 22, 2025
CVE-2025-14885
6.3

This vulnerability allows remote attackers to upload arbitrary files to SourceCodester Client Database Management System 1.0 via the /user_leads.php e...

Dec 18, 2025
CVE-2025-14522
6.3

This CVE describes an unrestricted file upload vulnerability in baowzh hfly's upload_json.php component. Attackers can remotely upload malicious files...

Dec 11, 2025
CVE-2025-14199
6.3

This vulnerability allows remote attackers to upload arbitrary files to Verysync 微力同步 web administration interface without proper restrictions...

Dec 7, 2025
CVE-2025-14195
6.3

This vulnerability allows remote attackers to upload arbitrary files to the Employee Profile Management System 1.0 via the /profiling/add_file_query.p...

Dec 7, 2025
CVE-2025-13949
6.3

This vulnerability in ProudMuBai GoFilm allows attackers to upload arbitrary files without restrictions via the SingleUpload function. It affects all ...

Dec 3, 2025
CVE-2025-13573
6.3

This vulnerability allows remote attackers to upload malicious files via the /add_book.php endpoint in projectworlds can pass software up to version 1...

Nov 24, 2025
CVE-2025-13544
6.3

This CVE describes an unrestricted file upload vulnerability in ashraf-kabir travel-agency software affecting the /customer_register.php endpoint. Att...

Nov 23, 2025
CVE-2025-13249
6.3

This vulnerability allows remote attackers to upload arbitrary files to Jiusi OA systems via the OfficeServer interface. Attackers can exploit this to...

Nov 16, 2025
CVE-2025-13238
6.3

Bdtask Flight Booking Software 4 contains an unrestricted file upload vulnerability in the agent profile edit functionality. Attackers can remotely up...

Nov 16, 2025
CVE-2025-13061
6.3

CVE-2025-13061 is an unrestricted file upload vulnerability in itsourcecode Online Voting System 1.0 that allows attackers to upload malicious files t...

Nov 12, 2025
CVE-2025-12862
6.3

CVE-2025-12862 is an unrestricted file upload vulnerability in projectworlds Online Notes Sharing Platform 1.0. Attackers can upload malicious files v...

Nov 7, 2025
CVE-2025-43412
6.3

A sandbox escape vulnerability in macOS allows malicious applications to bypass file quarantine restrictions and potentially access system resources o...

Nov 4, 2025
CVE-2025-27093
6.3

This vulnerability in Sliver's Wireguard netstack allows unrestricted communication between Wireguard clients, enabling compromised implants to attack...

Oct 28, 2025
CVE-2025-12347
6.3

This vulnerability in MaxSite CMS allows remote attackers to upload arbitrary files without proper restrictions. It affects MaxSite CMS versions up to...

Oct 28, 2025
CVE-2025-12346
6.3

This vulnerability in MaxSite CMS allows attackers to upload arbitrary files without restrictions by manipulating HTTP headers. It affects all MaxSite...

Oct 28, 2025
CVE-2025-12344
6.3

This vulnerability in Yonyou U8 Cloud allows attackers to upload arbitrary files without authentication by manipulating request headers. It affects al...

Oct 28, 2025
CVE-2025-12268
6.3

This vulnerability allows remote attackers to upload arbitrary files to LearnHouse's Course Thumbnail Handler API endpoint. Attackers can exploit this...

Oct 27, 2025
CVE-2025-12223
6.3

This vulnerability in Bdtask Flight Booking Software allows attackers to upload arbitrary files without restrictions via the Package Information Modul...

Oct 27, 2025
CVE-2025-61762
6.3

This vulnerability in Oracle PeopleSoft Enterprise FIN Payables 9.2 allows authenticated attackers with network access to modify or delete financial d...

Oct 21, 2025
CVE-2025-11908
6.3

This vulnerability allows remote attackers to upload arbitrary files to Shenzhen Ruiming Technology Streamax Crocus systems via the /FileDir.do?Action...

Oct 17, 2025
CVE-2025-11436
6.3

This vulnerability in JhumanJ OpnForm up to version 1.9.3 allows remote attackers to upload arbitrary files without restrictions via the /answer endpo...

Oct 8, 2025
CVE-2025-11426
6.3

Advanced Library Management System 1.0 contains an unrestricted file upload vulnerability in the edit_book.php file's image parameter. This allows rem...

Oct 8, 2025
CVE-2025-11417
6.3

Campcodes Advanced Online Voting Management System 1.0 contains an unrestricted file upload vulnerability in the /admin/voters_add.php endpoint. Attac...

Oct 8, 2025
CVE-2025-11398
6.3

SourceCodester Hotel and Lodge Management System 1.0 has an unrestricted file upload vulnerability in the profile.php image upload function. Attackers...

Oct 7, 2025
CVE-2025-11353
6.3

This vulnerability allows remote attackers to upload arbitrary files to the Online Hotel Reservation System 1.0 via the /admin/addgalleryexec.php endp...

Oct 7, 2025
CVE-2025-11351
6.3

CVE-2025-11351 is an unrestricted file upload vulnerability in code-projects Online Hotel Reservation System 1.0. Attackers can upload malicious files...

Oct 7, 2025

About Improper Access Control (CWE-284)

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Our database tracks 1,310 CVEs classified as CWE-284, with 216 rated critical and 557 rated high severity. The average CVSS score for Improper Access Control vulnerabilities is 7.2.

External reference: View CWE-284 on MITRE CWE →

Monitor Improper Access Control Vulnerabilities

Get alerted when new Improper Access Control CVEs affect your infrastructure.

Start Monitoring Free