Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,804
Assigned CVEs
15th
Commonality Rank
7.0
Avg CVSS
0.6%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-284 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
May 30, 2001
25 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

5,804 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-27348CRITICAL
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended t
Apr 22, 20249.899YESYES
CVE-2023-27350CRITICAL
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vu
Apr 20, 20239.899YESYES
CVE-2026-48907CRITICAL
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
Jun 5, 20269.898YESYES
CVE-2026-35616CRITICAL
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted re
Apr 4, 20269.898YESYES
CVE-2024-20767HIGH
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage
Mar 18, 20247.498YESYES
CVE-2023-26360CRITICAL
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Access Control vulnerability that could result in arbitrary code
Mar 23, 20239.898YESYES
CVE-2023-23752MEDIUM
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
Feb 16, 20235.398YESYES
CVE-2019-1653HIGH
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrie
Jan 24, 20197.598YESYES
CVE-2013-0422CRITICAL
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServe
Jan 10, 20139.898YESYES
CVE-2012-5076CRITICAL
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and
Oct 16, 20129.898YESYES
View all 5,804 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
10%
4.0-4.9
16%
19%
5.0-5.9
15%
16%
6.0-6.9
24%
26%
7.0-7.9
15%
11%
8.0-8.9
16%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
33 CVEs
0.6% of CVEs· 85th percentile
Metasploit
30 CVEs
0.5% of CVEs· 84th percentile
Nuclei
57 CVEs
1.0% of CVEs· 84th percentile
ExploitDB
78 CVEs
1.3% of CVEs· 84th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products