CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,270 vulnerabilities with CWE-284
CVE-2025-12480
CRITICAL
KEV
Triofox < 16.7.10368.56560 - Improper Access Control via Initial Setup Pages
CVSS 9.1
CVE-2025-64347
HIGH
Apollo Router < 1.61.12 and 2.8.1-rc.0 - Unauthorized Data Access via Renamed Access Control Directives
CVSS 7.5
CVE-2025-12862
MEDIUM
projectworlds Online Notes Sharing Platform 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-63686
MEDIUM
GuoMinJim PersonManage - File Download
CVSS 6.5
CVE-2025-27919
HIGH
AnyDesk < 9.0.4 - Unauthenticated Privilege Escalation via Full Access Profile Password Creation
CVSS 8.2
CVE-2025-12808
MEDIUM
Dvls Server <2025.3.5.0 - Info Disclosure
CVSS 6.5
CVE-2025-60784
MEDIUM
XiaozhangBang Voluntary Like System V8.8 - Info Disclosure
CVSS 6.5
CVE-2025-43418
MEDIUM
iOS <18.7.2 & <26.1 - Info Disclosure
CVSS 4.6
CVE-2025-57130
HIGH
ZwiiCMS < 13.6.07 - Authenticated Privilege Escalation via User Profile Modification
CVSS 8.3
CVE-2025-58337
MEDIUM
Doris MCP Server <0.6.0 - Auth Bypass
CVSS 5.4
CVE-2025-64110
HIGH
Cursor < 2.0 - Improper Access Control via cursorignore File Manipulation
CVSS 7.5
CVE-2025-62721
MEDIUM
LinkAce < 2.4.0 - Authenticated Improper Access Control in RSS Feed Endpoints
CVSS 6.5
CVE-2025-62720
MEDIUM
LinkAce < 2.4.0 - Authenticated Database Export via ExportController
CVSS 6.5
CVE-2025-43502
HIGH
Safari < 26.1 - Privacy Preference Bypass via Sensitive Data Exposure
CVSS 7.5
CVE-2025-43499
MEDIUM
macOS 14.0-14.8.1 - Unprotected User Data Exposure via Entitlement Bypass
CVSS 5.5
CVE-2025-43498
MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 5.5
CVE-2025-43495
MEDIUM
iOS <18.7.2 & <26.1 - Info Disclosure
CVSS 5.4
CVE-2025-43481
MEDIUM
macOS < 15.7.2 - Sandbox Escape via Improper Access Control
CVSS 5.2
CVE-2025-43477
MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Unprotected User Data Exposure via Log Entry Redaction
CVSS 5.5
CVE-2025-43476
HIGH
macOS <15.7.2, <26.1, <14.8.2 - Privilege Escalation
CVSS 7.8
CVE-2025-43454
HIGH
iPadOS < 26.1 - Improper Access Control
CVSS 7.5
CVE-2025-43450
HIGH
iOS <18.7.2 & <26.1 - Info Disclosure
CVSS 7.5
CVE-2025-43414
MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Unprotected User Data Exposure via Shortcuts App
CVSS 6.2
CVE-2025-43413
HIGH
Safari < 26.1 - Unauthenticated System-Wide Network Connection Observation via Sandbox Bypass
CVSS 7.5
CVE-2025-43412
MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - File Quarantine Bypass via Sandbox Escape
CVSS 6.3
Details
Vulnerabilities
5,270