The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
100 vulnerabilities with CWE-1220
CVE-2025-69196
MEDIUM
FastMCP OAuth Proxy token reuse across MCP servers
CVSS 6.5
CVE-2025-48517
MEDIUM
SEV firmware - Privilege Escalation
CVE-2025-48514
MEDIUM
SEV firmware - Privilege Escalation
CVE-2025-35998
HIGH
Intel(R) Quick Assist Technology - Privilege Escalation
CVSS 7.9
CVE-2025-11246
MEDIUM
GitLab CE/EE <18.5.5-18.7.1 - Privilege Escalation
CVSS 5.4
CVE-2025-8306
MEDIUM
Asseco InfoMedica - Info Disclosure
CVE-2025-20305
MEDIUM
Cisco Identity Services Engine - Authenticated Sensitive Information Disclosure via Web Interface
CVSS 4.3
CVE-2025-8053
CRITICAL
Opentext Flipper <3.1.2 - Privilege Escalation
CVSS 9.1
CVE-2025-8049
HIGH
Opentext Flipper <3.1.2 - Privilege Escalation
CVSS 8.8
CVE-2025-54461
MEDIUM
ChatLuck < V6.6 R2.0 - Unauthenticated Guest User Registration via Invitation Bypass
CVSS 5.3
CVE-2025-7493
CRITICAL
FreeIPA - Privilege Escalation via krbCanonicalName Validation Bypass
CVSS 9.1
CVE-2025-31961
LOW
HCL Connections - Unauthorized Data Update via Broken Access Control
CVSS 3.7
CVE-2025-2498
LOW
Gitlab EE <18.0.6-18.2.2 - Auth Bypass
CVSS 3.1
CVE-2025-22839
HIGH
Intel(R) Xeon(R) 6 Scalable - Privilege Escalation
CVSS 7.5
CVE-2025-7001
MEDIUM
GitLab CE/EE <18.0.5-18.2.1 - Privilege Escalation
CVSS 4.3
CVE-2025-3648
HIGH
ServiceNow Now Platform - Unauthenticated Data Inference via Range Query Requests
CVE-2025-27026
MEDIUM
Infinera G42 R6.1.3 - Privilege Escalation
CVSS 4.9
CVE-2025-4404
CRITICAL
Red Hat Enterprise Linux - Privilege Escalation via FreeIPA krbCanonicalName Uniqueness Bypass
CVSS 9.1
CVE-2025-5982
LOW
GitLab EE <17.10.8-18.0.2 - Auth Bypass
CVSS 3.7
CVE-2025-4979
MEDIUM
GitLab CE/EE <17.10.7-18.0.1 - Info Disclosure
CVSS 4.9
CVE-2025-1110
LOW
GitLab 18.0 - Insufficient Granularity of Access Control via GraphQL Query
CVSS 2.7
CVE-2025-32703
MEDIUM
Visual Studio 2017, 2019, 2022 - Information Disclosure via Insufficient Access Control
CVSS 5.5
CVE-2025-1278
MEDIUM
GitLab CE/EE <17.9.8-17.11.2 - Auth Bypass
CVSS 5.3
CVE-2025-31201
CRITICAL
KEV
macOS < 15.4.1 - Pointer Authentication Bypass via Insufficient Access Control
CVSS 9.8
CVE-2025-2408
MEDIUM
GitLab CE/EE <17.8.7-17.10.4 - Auth Bypass
CVSS 5.3
Details
Vulnerabilities
100