CWE-284: Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Yearly Trend
Top Affected Vendors
All Improper Access Control CVEs (1,311)
This critical vulnerability in Blogbook allows remote attackers to upload arbitrary files without restrictions via the image parameter in the admin po...
Jun 1, 2025This critical vulnerability in Realce Tecnologia Queue Ticket Kiosk allows remote attackers to upload arbitrary files without restrictions via the /ad...
May 26, 2025This critical vulnerability in H3C SecCenter SMP-E1114P02 allows remote attackers to upload arbitrary files without restrictions via the /safeEvent/im...
May 26, 2025CVE-2025-4735 is a critical unrestricted file upload vulnerability in Campcodes Sales and Inventory System 1.0. Attackers can remotely upload maliciou...
May 16, 2025This macOS vulnerability allows malicious applications to escape their sandbox restrictions, potentially accessing system resources or other applicati...
May 12, 2025CVE-2025-4538 is a critical unrestricted file upload vulnerability in kkFileView 4.4.0 that allows remote attackers to upload arbitrary files to the /...
May 11, 2025This critical vulnerability allows remote attackers to upload arbitrary files without restrictions in the feng_ha_ha/megagao ssm-erp and production_ss...
May 6, 2025CVE-2025-4291 is a critical unrestricted file upload vulnerability in IdeaCMS's saveUpload function that allows remote attackers to upload malicious f...
May 5, 2025This critical vulnerability in Youkefu allows remote attackers to upload arbitrary files without restrictions via the MediaController.java Upload func...
May 5, 2025OpenCTI versions 6.4.8 through 6.4.9 contain an authorization bypass vulnerability that allows authenticated users to modify restricted user attribute...
Apr 30, 2025This critical vulnerability in My-BBS 1.0 allows remote attackers to upload arbitrary files without restrictions via the UploadController endpoint. Th...
Apr 19, 2025This critical vulnerability in SourceCodester Web-based Pharmacy Product Management System 1.0 allows remote attackers to upload arbitrary files via t...
Apr 18, 2025This critical vulnerability in SourceCodester Web-based Pharmacy Product Management System 1.0 allows remote attackers to upload arbitrary files via t...
Apr 17, 2025This critical vulnerability in mymagicpower AIAS allows remote attackers to upload arbitrary files without restrictions, potentially leading to remote...
Apr 8, 2025CVE-2025-3324 is a critical unrestricted file upload vulnerability in Nimrod 0.8's FileRestController.java that allows remote attackers to upload arbi...
Apr 6, 2025CVE-2025-3040 is a critical unrestricted file upload vulnerability in Project Worlds Online Time Table Generator 1.0. Attackers can remotely upload ma...
Mar 31, 2025This critical vulnerability in College Management System 1.0 allows remote attackers to upload malicious files via the profile_image parameter in /Adm...
Mar 31, 2025CVE-2025-2952 is a critical unrestricted file upload vulnerability in Bluestar Micro Mall 1.0 that allows attackers to upload arbitrary files to the /...
Mar 30, 2025This critical vulnerability in Digiwin ERP 5.0.1 allows remote attackers to upload arbitrary files via the /Api/TinyMce/UploadAjaxAPI.ashx endpoint. A...
Mar 24, 2025This critical vulnerability in Yue Lao Blind Box software allows remote attackers to upload arbitrary files without restrictions via the base64image f...
Mar 23, 2025This critical vulnerability in LzCMS-LaoZhangBoKeXiTong allows attackers to upload arbitrary files without restrictions via the /admin/upload/upimage....
Mar 21, 2025This critical vulnerability in IROAD Dash Cam FX2 allows unauthenticated attackers on the local network to upload arbitrary files, potentially leading...
Mar 16, 2025This critical vulnerability in s-a-zhd Ecommerce-Website-using-PHP 1.0 allows remote attackers to upload arbitrary files via the name parameter in /cu...
Mar 6, 2025Apache Traffic Server versions 10.0.0 through 10.0.3 contain an improper access control vulnerability (CWE-284) that could allow unauthorized access t...
Mar 6, 2025CVE-2025-1835 is a critical unrestricted file upload vulnerability in osuuu LightPicture 1.2.2 that allows remote attackers to upload arbitrary files ...
Mar 2, 2025This critical vulnerability in zj1983 zz software allows remote attackers to upload arbitrary files without restrictions via the ZfileAction.upload fu...
Mar 2, 2025CVE-2025-1791 is a critical unrestricted file upload vulnerability in Zorlan SkyCaiji 2.9 that allows remote attackers to upload arbitrary files to th...
Mar 1, 2025CVE-2025-1166 is a critical unrestricted file upload vulnerability in SourceCodester Food Menu Manager 1.0. Attackers can remotely upload arbitrary fi...
Feb 11, 2025This critical vulnerability in Shanghai Lingdang Information Technology's Lingdang CRM allows remote attackers to upload arbitrary files without authe...
Jan 14, 2025This vulnerability allows attackers to upload arbitrary files without restrictions through the Change Image Handler component in Online Bike Rental Sy...
Jan 9, 2025This critical vulnerability in SingMR HouseRent 1.0 allows remote attackers to upload arbitrary files without restrictions via the singleUpload/upload...
Jan 9, 2025This vulnerability allows remote attackers to upload arbitrary files without restrictions in ZeroWdd myblog 1.0. Attackers can potentially upload mali...
Jan 8, 2025This critical vulnerability in My-Blog 1.0 allows remote attackers to upload arbitrary files without restrictions via the uploadFileByEditomd function...
Jan 6, 2025This critical vulnerability in ZeroWdd studentmanager 1.0 allows remote attackers to upload arbitrary files via the addTeacher/editTeacher functions. ...
Jan 5, 2025This critical vulnerability in ZeroWdd studentmanager 1.0 allows attackers to upload arbitrary files without restrictions through the addStudent/editS...
Jan 5, 2025This critical vulnerability in Tarzan CMS 1.0.0 allows remote attackers to upload arbitrary files without restrictions via the UploadResponse function...
Dec 29, 2024This critical vulnerability in Portfolio Management System MCA 1.0 allows remote attackers to upload arbitrary files via the /update_pd_process.php en...
Dec 26, 2024This critical vulnerability in Lingdang CRM allows attackers to upload arbitrary files without restrictions via the /crm/wechatSession/index.php endpo...
Nov 12, 2024This critical vulnerability in Codezips Online Institute Management System 1.0 allows remote attackers to upload arbitrary files via the /edit_user.ph...
Nov 8, 2024This vulnerability in Directus allows broken access control when using _in or _nin operators with empty arrays. Attackers can bypass intended permissi...
Jul 8, 2024Aquarius Desktop 3.0.069 for macOS stores user credentials in a local file using weak obfuscation that can be easily reversed, allowing attackers who ...
Dec 3, 2025This CVE describes a permissions bypass vulnerability in macOS Shortcuts that allows shortcuts to access files normally restricted from the Shortcuts ...
Nov 4, 2025phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability that allows attackers to manipulate session variables by controlling ...
Nov 20, 2025An unauthenticated vulnerability in Oracle Applications Manager allows attackers to modify or read limited data by tricking users into interacting wit...
Oct 21, 2025An unauthenticated attacker can exploit this vulnerability in Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC component via HTTP to modify or re...
Oct 21, 2025An unauthenticated attacker can exploit this vulnerability in Oracle Workflow Notification Mailer via HTTP to modify or read data. The attack requires...
Oct 21, 2025An unauthenticated attacker can exploit this vulnerability in Oracle iStore via HTTP to modify or read limited data, requiring interaction from anothe...
Oct 21, 2025This vulnerability in Oracle Universal Work Queue allows unauthenticated attackers with network access via HTTP to compromise the system. It affects O...
Jul 15, 2025This vulnerability in Oracle Business Intelligence Enterprise Edition allows unauthenticated attackers with network access via HTTP to compromise the ...
Jul 15, 2025An unauthenticated attacker can exploit this vulnerability in Oracle Application Object Library via HTTP to modify or read limited data, requiring use...
Apr 15, 2025About Improper Access Control (CWE-284)
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Our database tracks 1,311 CVEs classified as CWE-284, with 216 rated critical and 558 rated high severity. The average CVSS score for Improper Access Control vulnerabilities is 7.2.
External reference: View CWE-284 on MITRE CWE →
Monitor Improper Access Control Vulnerabilities
Get alerted when new Improper Access Control CVEs affect your infrastructure.
Start Monitoring Free