CWE-284: Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Yearly Trend
Top Affected Vendors
All Improper Access Control CVEs (1,310)
This vulnerability in Oracle Marketing allows unauthenticated attackers with network access via HTTP to compromise the system. It affects Oracle E-Bus...
Jul 16, 2024PublicCMS v4.0.202302.e contains an arbitrary file content replacement vulnerability in the /admin/cmsTemplate/replace component. This allows authenti...
Jul 12, 2024This CVE describes a Cross-Origin Resource Sharing (CORS) policy bypass vulnerability in Google Chrome that allows attackers to bypass discretionary a...
Jun 11, 2024This vulnerability in Polarion ALM allows authenticated users to bypass project access controls using the Apache Lucene query engine, enabling them to...
May 14, 2024CVE-2022-24972 is an authentication bypass vulnerability in TP-Link TL-WR940N routers that allows network-adjacent attackers to access stored credenti...
Mar 28, 2023Nokia SR Linux has an authentication bypass vulnerability in its JSON-RPC service that allows attackers to access the service without valid credential...
Jan 7, 2026This vulnerability in Oracle Applications Framework allows authenticated attackers with low privileges to perform unauthorized data manipulation (inse...
Jul 15, 2025This vulnerability in Absolute Persistence® allows attackers with physical device access and full network control to execute operating system command...
May 13, 2025CVE-2026-3748 is an unrestricted file upload vulnerability in Bytedesk's SVG file handler that allows attackers to upload malicious files without prop...
Mar 8, 2026This vulnerability allows remote attackers to upload arbitrary files to the sz-boot-parent application via the /api/admin/sys-file/upload API endpoint...
Feb 25, 2026CVE-2026-2978 is an unrestricted file upload vulnerability in FastApiAdmin's Scheduled Task API that allows remote attackers to upload arbitrary files...
Feb 23, 2026This vulnerability allows attackers to upload arbitrary files without restrictions to the Great Developers Certificate Generation System via the /rest...
Feb 8, 2026This vulnerability allows remote attackers to upload arbitrary files without restrictions through the updateAvatar function in guchengwuyue yshopmall....
Feb 8, 2026This vulnerability allows remote attackers to upload arbitrary files to bolo-solo blog systems due to insufficient validation in the FreeMarker templa...
Feb 4, 2026This vulnerability in code-projects Online Examination System 1.0 allows attackers to upload arbitrary files to the /admin_pic.php endpoint, potential...
Jan 26, 2026This vulnerability in EyouCMS allows attackers to perform unrestricted file uploads via manipulation of the 'viewfile' parameter in the Member Avatar ...
Jan 18, 2026This vulnerability allows remote attackers to upload arbitrary files to xiweicheng TMS systems without proper restrictions. Attackers can exploit this...
Jan 17, 2026This vulnerability allows remote attackers to upload arbitrary files to JavaMall applications due to insufficient restrictions in the MinioController ...
Jan 5, 2026CVE-2026-0577 is an unrestricted file upload vulnerability in code-projects Online Product Reservation System 1.0. Attackers can remotely upload malic...
Jan 4, 2026This vulnerability allows remote attackers to upload arbitrary files via the photo parameter in the student registration page of PHPGurukul Online Cou...
Jan 2, 2026This vulnerability allows remote attackers to upload arbitrary files via the image parameter in the userprofile.php file of College Notes Uploading Sy...
Dec 29, 2025This vulnerability allows remote attackers to upload arbitrary files to the moga-mall application by manipulating the objectName parameter in the addP...
Dec 28, 2025This vulnerability allows remote attackers to upload arbitrary files to the Student File Management System 1.0 via the /save_file.php endpoint. Attack...
Dec 24, 2025CVE-2025-15009 is an arbitrary file upload vulnerability in ChestnutCMS up to version 1.5.8 that allows attackers to upload malicious files to the ser...
Dec 22, 2025This vulnerability allows remote attackers to upload arbitrary files to SourceCodester Client Database Management System 1.0 via the /user_leads.php e...
Dec 18, 2025This CVE describes an unrestricted file upload vulnerability in baowzh hfly's upload_json.php component. Attackers can remotely upload malicious files...
Dec 11, 2025This vulnerability allows remote attackers to upload arbitrary files to Verysync 微力同步 web administration interface without proper restrictions...
Dec 7, 2025This vulnerability allows remote attackers to upload arbitrary files to the Employee Profile Management System 1.0 via the /profiling/add_file_query.p...
Dec 7, 2025This vulnerability in ProudMuBai GoFilm allows attackers to upload arbitrary files without restrictions via the SingleUpload function. It affects all ...
Dec 3, 2025This vulnerability allows remote attackers to upload malicious files via the /add_book.php endpoint in projectworlds can pass software up to version 1...
Nov 24, 2025This CVE describes an unrestricted file upload vulnerability in ashraf-kabir travel-agency software affecting the /customer_register.php endpoint. Att...
Nov 23, 2025This vulnerability allows remote attackers to upload arbitrary files to Jiusi OA systems via the OfficeServer interface. Attackers can exploit this to...
Nov 16, 2025Bdtask Flight Booking Software 4 contains an unrestricted file upload vulnerability in the agent profile edit functionality. Attackers can remotely up...
Nov 16, 2025CVE-2025-13061 is an unrestricted file upload vulnerability in itsourcecode Online Voting System 1.0 that allows attackers to upload malicious files t...
Nov 12, 2025CVE-2025-12862 is an unrestricted file upload vulnerability in projectworlds Online Notes Sharing Platform 1.0. Attackers can upload malicious files v...
Nov 7, 2025A sandbox escape vulnerability in macOS allows malicious applications to bypass file quarantine restrictions and potentially access system resources o...
Nov 4, 2025This vulnerability in Sliver's Wireguard netstack allows unrestricted communication between Wireguard clients, enabling compromised implants to attack...
Oct 28, 2025This vulnerability in MaxSite CMS allows remote attackers to upload arbitrary files without proper restrictions. It affects MaxSite CMS versions up to...
Oct 28, 2025This vulnerability in MaxSite CMS allows attackers to upload arbitrary files without restrictions by manipulating HTTP headers. It affects all MaxSite...
Oct 28, 2025This vulnerability in Yonyou U8 Cloud allows attackers to upload arbitrary files without authentication by manipulating request headers. It affects al...
Oct 28, 2025This vulnerability allows remote attackers to upload arbitrary files to LearnHouse's Course Thumbnail Handler API endpoint. Attackers can exploit this...
Oct 27, 2025This vulnerability in Bdtask Flight Booking Software allows attackers to upload arbitrary files without restrictions via the Package Information Modul...
Oct 27, 2025This vulnerability in Oracle PeopleSoft Enterprise FIN Payables 9.2 allows authenticated attackers with network access to modify or delete financial d...
Oct 21, 2025This vulnerability allows remote attackers to upload arbitrary files to Shenzhen Ruiming Technology Streamax Crocus systems via the /FileDir.do?Action...
Oct 17, 2025This vulnerability in JhumanJ OpnForm up to version 1.9.3 allows remote attackers to upload arbitrary files without restrictions via the /answer endpo...
Oct 8, 2025Advanced Library Management System 1.0 contains an unrestricted file upload vulnerability in the edit_book.php file's image parameter. This allows rem...
Oct 8, 2025Campcodes Advanced Online Voting Management System 1.0 contains an unrestricted file upload vulnerability in the /admin/voters_add.php endpoint. Attac...
Oct 8, 2025SourceCodester Hotel and Lodge Management System 1.0 has an unrestricted file upload vulnerability in the profile.php image upload function. Attackers...
Oct 7, 2025This vulnerability allows remote attackers to upload arbitrary files to the Online Hotel Reservation System 1.0 via the /admin/addgalleryexec.php endp...
Oct 7, 2025CVE-2025-11351 is an unrestricted file upload vulnerability in code-projects Online Hotel Reservation System 1.0. Attackers can upload malicious files...
Oct 7, 2025About Improper Access Control (CWE-284)
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Our database tracks 1,310 CVEs classified as CWE-284, with 216 rated critical and 557 rated high severity. The average CVSS score for Improper Access Control vulnerabilities is 7.2.
External reference: View CWE-284 on MITRE CWE →
Monitor Improper Access Control Vulnerabilities
Get alerted when new Improper Access Control CVEs affect your infrastructure.
Start Monitoring Free