CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,270 vulnerabilities with CWE-284
CVE-2025-13544 MEDIUM
ashraf-kabir travel-agency < 2025-07-05 - Unrestricted File Upload via /customer_register.php
CVSS 6.3
CVE-2025-31216 LOW
iPadOS < 17.7.7 and < 18.5 - Physical Access Managed Wi-Fi Profile Bypass
CVSS 2.4
CVE-2025-64483 MEDIUM
wazuh-dashboard-plugins 4.9.0-4.12.9 - Credential Exposure via /utils/configuration
CVE-2025-64660 HIGH
Visual Studio Code < 1.106.2 - Authenticated Remote Code Execution
CVSS 8.0
CVE-2025-48986 HIGH
Revive Adserver <6.0.1 - Auth Bypass
CVSS 8.8
CVE-2025-60799 MEDIUM
phpPgAdmin <7.13.0 - Code Injection
CVSS 6.1
CVE-2025-13443 MEDIUM
macrozheng mall < 1.0.3 - Incorrect Privilege Assignment via /member/readHistory/delete ids Parameter
CVSS 5.4
CVE-2025-13423 MEDIUM
Campcodes Retro Basketball Shoes Online Store 1.0 - Unrestricted File Upload via product_image Argument
CVSS 4.7
CVE-2025-13411 MEDIUM
Campcodes Retro Basketball Shoes Online Store 1.0 - Unrestricted File Upload via product_image Argument
CVSS 4.7
CVE-2025-63214 MEDIUM
bridgetech VBC Server & Element Manager 6.5.0-9, 6.5.0-10 - Unauthenticated Arbitrary Account Creation and Deletion
CVSS 6.5
CVE-2025-63223 CRITICAL
Axel Technology StreamerMAX MK II <1.0.3 - Auth Bypass
CVSS 9.8
CVE-2025-63221 CRITICAL
Axel Technology puma <1.0.3 - Auth Bypass
CVSS 9.1
CVE-2025-63219 HIGH
ITEL ISO FM SFN Adapter - Session Hijacking
CVSS 7.5
CVE-2025-63218 CRITICAL
Axel Technology WOLF1MS and WOLF2MS <=1.0.3 - Unauthenticated Admin Access
CVSS 9.8
CVE-2025-63225 CRITICAL
Eurolab ELTS100_UBX - Privilege Escalation
CVSS 9.8
CVE-2025-56499 MEDIUM
mihomo 1.19.11 - Authenticated Arbitrary File Read via External Control Key
CVSS 6.5
CVE-2025-37155 HIGH
ArubaOS-CX 10.10.0000-10.10.1169 - Authenticated Privilege Escalation via SSH Restricted Shell
CVSS 7.8
CVE-2025-53360 MEDIUM
pluginsGLPI's Database Inventory Plugin <1.0.3 - Privilege Escalation
CVSS 4.3
CVE-2025-41737 HIGH
metz-connect ewio2-m_firmware < 2.2.0 - Unauthenticated Source Code Disclosure via PHP Module
CVSS 7.5
CVE-2025-13275 MEDIUM
Iqbolshoh php-business-website <10677743a8dfc281f85291a27cf63a0bce0...
CVSS 4.7
CVE-2025-13250 MEDIUM
datax-web < 2.1.2 - Unauthenticated Improper Access Control in Job Handler
CVSS 6.3
CVE-2025-13249 MEDIUM
Jiusi OA <20251102 - Unrestricted Upload
CVSS 6.3
CVE-2025-13238 MEDIUM
Bdtask Flight Booking Software 4 - Unrestricted File Upload in Edit Profile Page
CVSS 6.3
CVE-2025-13198 MEDIUM
DouPHP <1.8 Release 20251022 - Unrestricted Upload
CVSS 4.7
CVE-2025-12182 MEDIUM
Qi Blocks <1.4.3 - Privilege Escalation
CVSS 4.3
Details
Vulnerabilities 5,270