CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,270 vulnerabilities with CWE-284
CVE-2025-65798
MEDIUM
usememos <0.25.2 - Privilege Escalation
CVSS 5.4
CVE-2025-65796
MEDIUM
usememos memos <0.25.2 - Privilege Escalation
CVSS 4.3
CVE-2025-14219
MEDIUM
Campcodes Retro Basketball Shoes Online Store 1.0 - Unrestricted File Upload via product_image Argument
CVSS 4.7
CVE-2025-14199
MEDIUM
Verysync <2.21.3 - Unrestricted Upload
CVSS 6.3
CVE-2025-14198
MEDIUM
Verysync 微力同步 2.21.3 - Info Disclosure
CVSS 5.3
CVE-2025-14197
MEDIUM
Verysync <= 2.21.3 - Information Disclosure in Web Administration Module
CVSS 5.3
CVE-2025-14195
MEDIUM
Employee Profile Management System 1.0 - Unrestricted File Upload via per_file Argument
CVSS 6.3
CVE-2025-66557
MEDIUM
Nextcloud Deck <1.14.6-1.15.2 - Privilege Escalation
CVSS 5.4
CVE-2025-14086
MEDIUM
youlai-mall 1.0.0/2.0.0 - Improper Access Control via OpenID Parameter
CVSS 6.3
CVE-2025-14052
MEDIUM
youlai-mall 1.0.0/2.0.0 - Improper Access Control in getMemberById Function
CVSS 6.3
CVE-2025-66509
CRITICAL
LaraDashboard < 2.3.0 - Unauthenticated Arbitrary Code Execution via Host Header Spoofing
CVSS 9.8
CVE-2025-63363
HIGH
Waveshare RS232/485 TO WIFI ETH - DoS
CVSS 7.5
CVE-2025-63681
MEDIUM
open-webui <0.6.33 - Privilege Escalation
CVSS 4.3
CVE-2025-57213
HIGH
platform v1.0.0 - Improper Access Control in orderService.queryObject
CVSS 7.5
CVE-2025-57212
HIGH
platform 1.0.0 - Improper Access Control in ApiOrderService.java
CVSS 7.5
CVE-2025-57210
HIGH
platform 1.0.0 - Improper Access Control in ApiPayController
CVSS 7.5
CVE-2025-65097
MEDIUM
RomM <4.4.1-4.4.1-beta.2 - Privilege Escalation
CVSS 6.5
CVE-2025-65096
MEDIUM
RomM <4.4.1-4.4.1-beta.2 - Info Disclosure
CVSS 4.3
CVE-2025-65841
MEDIUM
Aquarius Desktop 3.0.069 - Info Disclosure
CVSS 6.2
CVE-2025-13949
MEDIUM
ProudMuBai GoFilm <1.0.1 - Unrestricted Upload
CVSS 6.3
CVE-2025-59703
CRITICAL
Entrust nShield HSM <13.6.12 - Physical Tampering via F14 Attack
CVSS 9.1
CVE-2025-59702
HIGH
Entrust nShield HSM <13.6.12 Authenticated Tamper Event Falsification
CVSS 7.2
CVE-2025-59697
HIGH
Entrust nShield HSM <13.6.12 Privilege Escalation via GRUB
CVSS 7.2
CVE-2025-55749
HIGH
XWiki <16.10.11, 17.4.4, 17.7.0 - Info Disclosure
CVSS 7.5
CVE-2025-61229
HIGH
Shirt Pocket's SuperDuper! <3.10 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
5,270