CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,270 vulnerabilities with CWE-284
CVE-2025-66911 MEDIUM
Turms IM Server <= 0.10.0-SNAPSHOT - Authenticated Improper Access Control in User Online Status Query
CVSS 6.5
CVE-2025-64400 MEDIUM
Control Panel - Privilege Escalation
CVSS 4.1
CVE-2025-63387 HIGH
Dify 1.9.1 - Unauthenticated Sensitive Data Exposure via System Features Endpoint
CVSS 7.5
CVE-2025-14885 MEDIUM
SourceCodester Client Database Management System 1.0 - Unrestricted File Upload in Leads Generation Module
CVSS 6.3
CVE-2025-67789 MEDIUM
DriveLock 24.1-24.1.5, 24.2-24.2.6, 25.1-25.1.4 - Authenticated Information Disclosure via API
CVSS 5.3
CVE-2025-46292 MEDIUM
iPadOS < 18.7.3 - Unprotected User Data Exposure via Entitlement Bypass
CVSS 5.5
CVE-2025-46288 MEDIUM
iPadOS < 26.2 - Unauthorized Access to Sensitive Payment Tokens
CVSS 5.5
CVE-2025-46282 MEDIUM
macOS Tahoe <26.2 - Info Disclosure
CVSS 5.5
CVE-2025-66397 HIGH
ChurchCRM <6.5.3 - Privilege Escalation
CVSS 8.3
CVE-2025-14095 MEDIUM
Radiometer Products - Privilege Escalation
CVSS 6.8
CVE-2025-11901 HIGH
ASUS Motherboards - Uncontrolled Resource Consumption
CVE-2025-14749 MEDIUM
Ningyuanda TC155 57.0.2.0 - Unauthenticated Incorrect Privilege Assignment in ONVIF PTZ Control Interface
CVSS 6.3
CVE-2025-14748 MEDIUM
Ningyuanda TC155 57.0.2.0 - Unauthenticated Hard Reset via ONVIF Device Management Service
CVSS 5.4
CVE-2025-67715 MEDIUM
Weblate < 5.15 - Unauthenticated User Information Disclosure via API
CVSS 4.3
CVE-2025-55895 CRITICAL
TOTOLINK A3300R <17.0.0cu.557 - Remote RCE
CVSS 9.1
CVE-2025-65176 HIGH
Dynatrace OneAgent < 1.325.47 - Unauthenticated NTLM Relay Attack via Network Share Access
CVSS 7.5
CVE-2025-65780 HIGH
Wekan <18.15 - Privilege Escalation
CVSS 8.8
CVE-2025-65779 HIGH
Wekan < 8.16 - Unauthenticated Board Reordering via Sort Value Manipulation
CVSS 7.5
CVE-2025-14660 MEDIUM
DecoCMS Mesh <1.0.0-alpha.31 - Improper Access Control
CVSS 5.6
CVE-2025-14642 MEDIUM
Computer Laboratory System 1.0 - Unrestricted Upload
CVSS 4.7
CVE-2025-14641 MEDIUM
Computer Laboratory System 1.0 - Unrestricted Upload
CVSS 4.7
CVE-2025-14583 HIGH
campcodes Online Student Enrollment System 1.0 - Unrestricted Upload
CVSS 7.3
CVE-2025-14582 MEDIUM
campcodes Online Student Enrollment System 1.0 - Unrestricted Upload
CVSS 4.7
CVE-2025-43518 LOW
Apple watchOS <26.2 - Info Disclosure
CVSS 3.3
CVE-2025-43513 MEDIUM
macOS <26.2-15.7.3-14.8.3 - Info Disclosure
CVSS 5.5
Details
Vulnerabilities 5,270