CWE-284: Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

1,310
Total CVEs
216
Critical
557
High
7.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
124
2025
669
2024
305
2023
121
2022
36

Top Affected Vendors

1 Microsoft 84
2 Apple 79
3 Oracle 57
4 Intel 32
5 Cisco 22
6 Adobe 21
7 Dell 19
8 Fabian 17
9 Mattermost 12
10 Campcodes 11

All Improper Access Control CVEs (1,310)

CVE-2025-11320
6.3

This vulnerability allows remote attackers to upload arbitrary files without restrictions in the wisdom-education application. Attackers can exploit t...

Oct 6, 2025
CVE-2025-11078
6.3

CVE-2025-11078 is an unrestricted file upload vulnerability in itsourcecode Open Source Job Portal 1.0 that allows remote attackers to upload arbitrar...

Sep 27, 2025
CVE-2025-10763
6.3

This vulnerability allows remote attackers to upload arbitrary files to the academico-sis system via the /edit-photo endpoint in the Profile Picture H...

Sep 21, 2025
CVE-2025-10741
6.3

This vulnerability in Selleo Mentingo allows attackers to upload arbitrary files via the Profile Picture Handler component by manipulating the userAva...

Sep 20, 2025
CVE-2025-10616
6.3

CVE-2025-10616 is an unrestricted file upload vulnerability in itsourcecode E-Commerce Website 1.0 that allows remote attackers to upload arbitrary fi...

Sep 17, 2025
CVE-2025-10615
6.3

This vulnerability in itsourcecode E-Commerce Website 1.0 allows attackers to upload arbitrary files to the /admin/products.php endpoint without prope...

Sep 17, 2025
CVE-2025-10480
6.3

This vulnerability allows remote attackers to upload arbitrary files to SourceCodester Online Student File Management System 1.0 via the /save_file.ph...

Sep 15, 2025
CVE-2025-10428
6.3

This vulnerability allows remote attackers to upload arbitrary files to SourceCodester Pet Grooming Management Software 1.0 via the website_image para...

Sep 15, 2025
CVE-2025-10398
6.3

This vulnerability allows remote attackers to upload arbitrary files to the fcba_zzm ics-park Smart Park Management System 2.0 due to insufficient val...

Sep 14, 2025
CVE-2025-10085
6.3

This vulnerability allows remote attackers to upload arbitrary files to SourceCodester Pet Grooming Management Software 1.0 via the manage_website.php...

Sep 8, 2025
CVE-2025-9942
6.3

CodeAstro Real Estate Management System 1.0 contains an unrestricted file upload vulnerability in the submitproperty.php endpoint. This allows remote ...

Sep 4, 2025
CVE-2025-9941
6.3

CodeAstro Real Estate Management System 1.0 has an unrestricted file upload vulnerability in the /register.php component. Attackers can remotely uploa...

Sep 4, 2025
CVE-2025-9847
6.3

CVE-2025-9847 is an unrestricted file upload vulnerability in ScriptAndTools Real Estate Management System 1.0. Attackers can upload malicious files v...

Sep 3, 2025
CVE-2025-9841
6.3

This vulnerability allows remote attackers to upload arbitrary files to Mobile Shop Management System 1.0 servers via the ProductImage parameter in Ad...

Sep 3, 2025
CVE-2025-9800
6.3

This vulnerability allows remote attackers to upload arbitrary files to SimStudioAI sim applications due to insufficient validation in the HTML File P...

Sep 1, 2025
CVE-2025-9415
6.3

This vulnerability in GreenCMS allows attackers to upload arbitrary files without restrictions via the /index.php?m=admin&c=media&a=fileconnect endpoi...

Aug 25, 2025
CVE-2025-9406
6.3

This vulnerability allows remote attackers to upload arbitrary files without restrictions in xuhuisheng lemon CMS versions up to 1.13.0. The flaw exis...

Aug 25, 2025
CVE-2025-9400
6.3

This vulnerability in YiFang CMS allows remote attackers to upload arbitrary files without restrictions through the mergeMultipartUpload function. It ...

Aug 25, 2025
CVE-2025-9397
6.3

CVE-2025-9397 is an unrestricted file upload vulnerability in givanz Vvveb CMS that allows remote attackers to upload arbitrary files to the server. T...

Aug 24, 2025
CVE-2025-9153
6.3

This vulnerability allows remote attackers to upload arbitrary files to the Online Tour and Travel Management System 1.0 via the photo parameter in /a...

Aug 19, 2025
CVE-2025-9099
6.3

Acrel Environmental Monitoring Cloud Platform up to version 20250804 contains an unrestricted file upload vulnerability in the /NewsManage/UploadNewsI...

Aug 18, 2025
CVE-2025-8859
6.3

CVE-2025-8859 is an unrestricted file upload vulnerability in eBlog Site 1.0's admin panel. Attackers can upload malicious files to the server via the...

Aug 11, 2025
CVE-2025-8841
6.3

This vulnerability allows remote attackers to upload arbitrary files to zlt2000 microservices-platform servers without proper restrictions. Affected s...

Aug 11, 2025
CVE-2025-8775
6.3

This critical vulnerability in Qiyuesuo Electronic Signature Platform allows remote attackers to upload arbitrary files without restrictions via the /...

Aug 9, 2025
CVE-2025-8764
6.3

This critical vulnerability in linlinjava litemall allows remote attackers to upload arbitrary files without restrictions via the /wx/storage/upload e...

Aug 9, 2025
CVE-2025-8526
6.3

This critical vulnerability in Exrick xboot allows remote attackers to upload arbitrary files without restrictions via the UploadController.java compo...

Aug 4, 2025
CVE-2025-8504
6.3

This critical vulnerability in Kitchen Treasure 1.0 allows remote attackers to upload arbitrary files via the photo parameter in userregistration.php....

Aug 3, 2025
CVE-2025-8344
6.3

This critical vulnerability in openviglet shio allows remote attackers to upload arbitrary files without restrictions via the shStaticFileUpload funct...

Jul 31, 2025
CVE-2025-8174
6.3

This critical vulnerability in code-projects Voting System 1.0 allows remote attackers to upload arbitrary files via the photo parameter in /admin/can...

Jul 26, 2025
CVE-2025-8171
6.3

This critical vulnerability in code-projects Document Management System 1.0 allows remote attackers to upload arbitrary files via the /insert.php endp...

Jul 25, 2025
CVE-2025-7906
6.3

This critical vulnerability in RuoYi allows attackers to upload arbitrary files without restrictions via the uploadFile function. Remote attackers can...

Jul 20, 2025
CVE-2025-7895
6.3

This critical vulnerability in MoneyPrinterTurbo allows remote attackers to upload arbitrary files without restrictions via the upload_bgm_file functi...

Jul 20, 2025
CVE-2025-7879
6.3

This vulnerability allows remote attackers to upload arbitrary files to Metasoft MetaCRM systems via the mobileupload.jsp endpoint. Affected are all M...

Jul 20, 2025
CVE-2025-7877
6.3

This critical vulnerability in Metasoft MetaCRM allows remote attackers to upload arbitrary files via the sendfile.jsp endpoint. Affected systems incl...

Jul 20, 2025
CVE-2025-7864
6.3

This critical vulnerability in JeeSite allows attackers to upload arbitrary files without proper restrictions, potentially leading to remote code exec...

Jul 20, 2025
CVE-2025-7755
6.3

CVE-2025-7755 is a critical unrestricted file upload vulnerability in code-projects Online Ordering System 1.0. Attackers can remotely upload maliciou...

Jul 17, 2025
CVE-2025-7627
6.3

This critical vulnerability in YiJiuSmile kkFileViewOfficeEdit allows remote attackers to upload arbitrary files without restrictions via the /fileUpl...

Jul 14, 2025
CVE-2025-7487
6.3

This critical vulnerability in JoeyBling SpringBoot_MyBatisPlus allows remote attackers to upload arbitrary files without restrictions via the SysFile...

Jul 12, 2025
CVE-2025-7412
6.3

CVE-2025-7412 is a critical unrestricted file upload vulnerability in code-projects Library System 1.0. Attackers can remotely upload malicious files ...

Jul 10, 2025
CVE-2025-7175
6.3

This critical vulnerability in code-projects E-Commerce Site 1.0 allows remote attackers to upload arbitrary files via the photo parameter in /admin/u...

Jul 8, 2025
CVE-2025-7151
6.3

This critical vulnerability in Campcodes Advanced Online Voting System 1.0 allows remote attackers to upload arbitrary files via the photo parameter i...

Jul 7, 2025
CVE-2025-7075
6.3

CVE-2025-7075 is a critical vulnerability in BlackVue Dashcam 590X devices that allows unauthenticated attackers on the local network to upload arbitr...

Jul 6, 2025
CVE-2025-6900
6.3

This critical vulnerability in code-projects Library System 1.0 allows remote attackers to upload arbitrary files via the /add-book.php endpoint's ima...

Jun 30, 2025
CVE-2023-29113
6.3

This vulnerability in MIB3 infotainment units allows attackers with existing system access to bypass operating system access controls through the inte...

Jun 28, 2025
CVE-2025-45729
6.3

D-Link DIR-823-Pro router firmware version 1.02 has improper permission control that allows unauthorized users to enable and access Telnet services re...

Jun 27, 2025
CVE-2025-6667
6.3

This critical vulnerability in code-projects Car Rental System 1.0 allows remote attackers to upload arbitrary files via the /admin/add_cars.php endpo...

Jun 25, 2025
CVE-2025-6466
6.3

This critical vulnerability in ageerle ruoyi-ai 2.0.0 allows remote attackers to upload arbitrary files without restrictions via the speechToTextTrans...

Jun 22, 2025
CVE-2025-5873
6.3

This vulnerability allows remote attackers to upload arbitrary files to eCharge Hardy Barth Salia PLCC devices via the /firmware.php endpoint in the W...

Jun 9, 2025
CVE-2025-5728
6.3

This critical vulnerability in SourceCodester Open Source Clinic Management System 1.0 allows remote attackers to upload arbitrary files via the websi...

Jun 6, 2025
CVE-2025-5406
6.3

This critical vulnerability in Blogbook allows remote attackers to upload arbitrary files without restrictions via the image parameter in the admin po...

Jun 1, 2025

About Improper Access Control (CWE-284)

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Our database tracks 1,310 CVEs classified as CWE-284, with 216 rated critical and 557 rated high severity. The average CVSS score for Improper Access Control vulnerabilities is 7.2.

External reference: View CWE-284 on MITRE CWE →

Monitor Improper Access Control Vulnerabilities

Get alerted when new Improper Access Control CVEs affect your infrastructure.

Start Monitoring Free