CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
8,213 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 1 of 165
- CVE-2026-48939CRITICALCVSS 10.0EG 10.0⚠ KEV2026-06-20
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
- CVE-2026-34908CRITICALCVSS 10.0EG 10.0⚠ KEV2026-05-22
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.
- CVE-2026-21962CRITICALCVSS 10.0EG 10.0⚠ KEV2026-01-20
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions…
- CVE-2024-45519CRITICALCVSS 10.0EG 10.0⚠ KEV2024-10-02
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
- CVE-2023-7028CRITICALCVSS 10.0EG 10.0⚠ KEV2024-01-12
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which …
- CVE-2015-3306CRITICALCVSS 10.0EG 10.0⚠ KEV2015-05-18
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
- CVE-2026-56290CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-29
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and l…
- CVE-2026-48908CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-20
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
- CVE-2026-48907CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-05
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
- CVE-2026-35616CRITICALCVSS 9.8EG 9.8⚠ KEV2026-04-04
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
- CVE-2025-61882CRITICALCVSS 9.8EG 9.8⚠ KEV2025-10-05
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated a…
- CVE-2024-40766CRITICALCVSS 9.8EG 9.8⚠ KEV2024-08-23
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects Soni…
- CVE-2024-27348CRITICALCVSS 9.8EG 9.8⚠ KEV2024-04-22
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth sy…
- CVE-2023-24489CRITICALCVSS 9.8EG 9.8⚠ KEV2023-07-10
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
- CVE-2023-27350CRITICALCVSS 9.8EG 9.8⚠ KEV2023-04-20
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompl…
- CVE-2021-22941CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-23
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
- CVE-2019-11634CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-22
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
- CVE-2016-3427CRITICALCVSS 9.8EG 9.8⚠ KEV2016-04-21
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
- CVE-2013-0422CRITICALCVSS 9.8EG 9.8⚠ KEV2013-01-10
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiato…
- CVE-2012-5076CRITICALCVSS 9.8EG 9.8⚠ KEV2012-10-16
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.
- CVE-2012-4681CRITICALCVSS 9.8EG 9.8⚠ KEV2012-08-28
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using…
- CVE-2012-1723CRITICALCVSS 9.8EG 9.8⚠ KEV2012-06-16
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentialit…
- CVE-2011-3544CRITICALCVSS 9.8EG 9.8⚠ KEV2011-10-19
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integ…
- CVE-2020-2506CRITICALCVSS 7.3EG 9.8⚠ KEV2021-02-03
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive i…
- CVE-2025-12480CRITICALCVSS 9.1EG 9.1⚠ KEV2025-11-10
Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.
- CVE-2025-33073CRITICALCVSS 8.8EG 9.0⚠ KEV2025-06-10
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
- CVE-2016-7256CRITICALCVSS 8.8EG 9.0⚠ KEV2016-11-10
atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016…
- CVE-2023-26360CRITICALCVSS 8.6EG 9.0⚠ KEV2023-03-23
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
- CVE-2025-24989CRITICALCVSS 8.2EG 9.0⚠ KEV2025-02-19
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service …
- CVE-2026-81963CRITICALCVSS 7.8EG 9.0⚠ KEV2026-09-08
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
- CVE-2025-59230CRITICALCVSS 7.8EG 9.0⚠ KEV2025-10-14
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- CVE-2016-3393CRITICALCVSS 7.8EG 9.0⚠ KEV2016-10-14
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote …
- CVE-2023-38205CRITICALCVSS 7.5EG 9.0⚠ KEV2023-09-14
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnera…
- CVE-2023-29298CRITICALCVSS 7.5EG 9.0⚠ KEV2023-07-12
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage thi…
- CVE-2019-1653CRITICALCVSS 7.5EG 9.0⚠ KEV2019-01-24
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive information. The vulnerability is due to impro…
- CVE-2024-20767CRITICALCVSS 7.4EG 9.0⚠ KEV2024-03-18
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. E…
- CVE-2020-8193CRITICALCVSS 6.5EG 9.0⚠ KEV2020-07-10
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to cer…
- CVE-2016-3715CRITICALCVSS 5.5EG 9.0⚠ KEV2016-05-05
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
- CVE-2025-31125CRITICALCVSS 5.3EG 9.0⚠ KEV2025-03-31
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option…
- CVE-2023-23752CRITICALCVSS 5.3EG 9.0⚠ KEV2023-02-16
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
- CVE-2015-4902CRITICALCVSS 5.3EG 9.0⚠ KEV2015-10-22
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
- CVE-2020-8196CRITICALCVSS 4.3EG 9.0⚠ KEV2020-07-10
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information dis…
- CVE-2022-23134CRITICALCVSS 3.7EG 9.0⚠ KEV2022-01-13
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Fro…
- CVE-2013-2423CRITICALCVSS 3.7EG 9.0⚠ KEV2013-04-17
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous inf…
- CVE-2026-97163CRITICALCVSS 10.0EG 10.02026-09-26
Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
- CVE-2026-20192CRITICALCVSS 10.0EG 10.02026-09-16
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security…
- CVE-2026-87230CRITICALCVSS 10.0EG 10.02026-09-15
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with ne…
- CVE-2026-54745CRITICALCVSS 10.0EG 10.02026-08-28
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ …
- CVE-2026-18886CRITICALCVSS 10.0EG 10.02026-08-27
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyo…
- CVE-2026-76607CRITICALCVSS 10.0EG 10.02026-08-22
Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →