CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,270 vulnerabilities with CWE-284
CVE-2025-43416
MEDIUM
macOS <26.2, <15.7.3, <14.8.3 - Info Disclosure
CVSS 5.5
CVE-2025-43404
LOW
macOS Tahoe <26.1 - Info Disclosure
CVSS 3.3
CVE-2025-43393
MEDIUM
macOS Tahoe <26.1 - Privilege Escalation
CVSS 5.2
CVE-2025-43351
MEDIUM
macOS < 26.1 - Unprotected User Data Exposure via Permissions Issue
CVSS 5.5
CVE-2025-66430
CRITICAL
Plesk 18.0.70-18.0.73.4 and 18.0.74 - Improper Access Control
CVSS 9.1
CVE-2025-64669
HIGH
Windows Admin Center < 2511 and 1809.0-2.6.5.16 - Authenticated Privilege Escalation
CVSS 7.8
CVE-2025-14530
MEDIUM
Real Estate Property Listing App 1.0 - Unrestricted File Upload via Image Argument in /admin/property.php
CVSS 4.7
CVE-2025-14528
MEDIUM
D-Link DIR-803 <1.04 - Info Disclosure
CVSS 5.3
CVE-2025-14522
MEDIUM
baowzh hfly < 2016-05-11 - Unrestricted File Upload via imgFile Parameter
CVSS 6.3
CVE-2025-67510
CRITICAL
neuron-ai < 2.8.12 - Unauthenticated Arbitrary SQL Execution via MySQLWriteTool
CVSS 9.4
CVE-2025-24857
HIGH
U-Boot <2017.11 - Memory Corruption
CVSS 7.6
CVE-2025-14082
LOW
Keycloak < 26.5.0 - Unauthenticated Sensitive Role Metadata Exposure via Admin REST API
CVSS 2.7
CVE-2025-64897
MEDIUM
ColdFusion <= 2025.4, 2023.16, 2021.22 - Improper Access Control
CVSS 5.6
CVE-2025-65594
HIGH
OpenSIS < 9.2 - Authenticated Incorrect Access Control in Student.php
CVSS 8.1
CVE-2025-64673
HIGH
Windows 10/11 & Server 2019/2022/2025 - Privilege Escalation via Storvsp.sys
CVSS 7.8
CVE-2025-62570
HIGH
Windows 11 24H2/25H2 and Windows Server 2025 - Information Disclosure via Camera Frame Server Monitor
CVSS 7.1
CVE-2025-62474
HIGH
Windows Remote Access Connection Manager - Authenticated Privilege Escalation via Improper Access Control
CVSS 7.8
CVE-2025-59923
LOW
Fortinet FortiAuthenticator 6.3.0-6.6.6 - Authenticated Credential Disclosure via Crafted Requests
CVSS 2.7
CVE-2025-59810
MEDIUM
FortiSOAR 7.3.0-7.5.1, 7.6.0-7.6.2 - Authenticated Information Disclosure via Crafted Requests
CVSS 6.5
CVE-2025-59517
HIGH
Windows Storage VSP Driver - Authenticated Privilege Escalation
CVSS 7.8
CVE-2025-63739
MEDIUM
Xinhu Rainrock RockOA <2.7.0 - Command Injection
CVSS 4.3
CVE-2025-40939
MEDIUM
SIMATIC CN 4100 < 4.0.1 - Unauthenticated Denial of Service via USB Port
CVSS 4.6
CVE-2025-14286
MEDIUM
Tenda AC9 15.03.05.14_multi - Info Disclosure
CVSS 5.3
CVE-2025-65797
MEDIUM
usememos memos <0.25.2 - Privilege Escalation
CVSS 6.5
CVE-2025-65795
HIGH
usememos memos <0.25.2 - Privilege Escalation
CVSS 7.5
Details
Vulnerabilities
5,270