CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,270 vulnerabilities with CWE-284
CVE-2025-65798 MEDIUM
usememos <0.25.2 - Privilege Escalation
CVSS 5.4
CVE-2025-65796 MEDIUM
usememos memos <0.25.2 - Privilege Escalation
CVSS 4.3
CVE-2025-14219 MEDIUM
Campcodes Retro Basketball Shoes Online Store 1.0 - Unrestricted File Upload via product_image Argument
CVSS 4.7
CVE-2025-14199 MEDIUM
Verysync <2.21.3 - Unrestricted Upload
CVSS 6.3
CVE-2025-14198 MEDIUM
Verysync 微力同步 2.21.3 - Info Disclosure
CVSS 5.3
CVE-2025-14197 MEDIUM
Verysync <= 2.21.3 - Information Disclosure in Web Administration Module
CVSS 5.3
CVE-2025-14195 MEDIUM
Employee Profile Management System 1.0 - Unrestricted File Upload via per_file Argument
CVSS 6.3
CVE-2025-66557 MEDIUM
Nextcloud Deck <1.14.6-1.15.2 - Privilege Escalation
CVSS 5.4
CVE-2025-14086 MEDIUM
youlai-mall 1.0.0/2.0.0 - Improper Access Control via OpenID Parameter
CVSS 6.3
CVE-2025-14052 MEDIUM
youlai-mall 1.0.0/2.0.0 - Improper Access Control in getMemberById Function
CVSS 6.3
CVE-2025-66509 CRITICAL
LaraDashboard < 2.3.0 - Unauthenticated Arbitrary Code Execution via Host Header Spoofing
CVSS 9.8
CVE-2025-63363 HIGH
Waveshare RS232/485 TO WIFI ETH - DoS
CVSS 7.5
CVE-2025-63681 MEDIUM
open-webui <0.6.33 - Privilege Escalation
CVSS 4.3
CVE-2025-57213 HIGH
platform v1.0.0 - Improper Access Control in orderService.queryObject
CVSS 7.5
CVE-2025-57212 HIGH
platform 1.0.0 - Improper Access Control in ApiOrderService.java
CVSS 7.5
CVE-2025-57210 HIGH
platform 1.0.0 - Improper Access Control in ApiPayController
CVSS 7.5
CVE-2025-65097 MEDIUM
RomM <4.4.1-4.4.1-beta.2 - Privilege Escalation
CVSS 6.5
CVE-2025-65096 MEDIUM
RomM <4.4.1-4.4.1-beta.2 - Info Disclosure
CVSS 4.3
CVE-2025-65841 MEDIUM
Aquarius Desktop 3.0.069 - Info Disclosure
CVSS 6.2
CVE-2025-13949 MEDIUM
ProudMuBai GoFilm <1.0.1 - Unrestricted Upload
CVSS 6.3
CVE-2025-59703 CRITICAL
Entrust nShield HSM <13.6.12 - Physical Tampering via F14 Attack
CVSS 9.1
CVE-2025-59702 HIGH
Entrust nShield HSM <13.6.12 Authenticated Tamper Event Falsification
CVSS 7.2
CVE-2025-59697 HIGH
Entrust nShield HSM <13.6.12 Privilege Escalation via GRUB
CVSS 7.2
CVE-2025-55749 HIGH
XWiki <16.10.11, 17.4.4, 17.7.0 - Info Disclosure
CVSS 7.5
CVE-2025-61229 HIGH
Shirt Pocket's SuperDuper! <3.10 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 5,270