CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,280 vulnerabilities with CWE-284
CVE-2025-12268
MEDIUM
LearnHouse < 2025-09-21 - Unrestricted File Upload via Course Thumbnail Handler
CVSS 6.3
CVE-2025-12223
MEDIUM
Bdtask Flight Booking Software < 3.1 - Unrestricted File Upload in Package Information Module
CVSS 6.3
CVE-2025-12222
MEDIUM
Bdtask Flight Booking Software < 3.1 - Unrestricted File Upload via Deposit Handler
CVSS 6.3
CVE-2025-12201
MEDIUM
ajayrandhawa user-management-php-mysql < 2023-03-16 - Unrestricted File Upload via Image Argument
CVSS 4.7
CVE-2025-6680
MEDIUM
Tutor LMS < 3.8.3 - Authenticated Sensitive Information Exposure via Assignment Review
CVSS 4.3
CVE-2025-59500
HIGH
Azure Notification Service - Privilege Escalation via Improper Access Control
CVSS 7.7
CVE-2025-59273
HIGH
Azure Event Grid - Unauthenticated Privilege Escalation
CVSS 7.3
CVE-2025-62713
HIGH
Kottster 3.2.0-3.3.1 - Unauthenticated Remote Code Execution in Development Mode
CVE-2025-62395
MEDIUM
moodle 4.1.0-4.1.20 - Improper Access Control in Cohort Search Web Service
CVSS 4.3
CVE-2025-62393
MEDIUM
moodle 5.0.0-5.0.3 - Improper Access Control in Course Overview Output
CVSS 4.3
CVE-2025-62290
HIGH
Oracle ZFS Storage Appliance Kit 8.8 - Remote Code Execution via Block Storage Component
CVSS 7.2
CVE-2025-61881
MEDIUM
Oracle Java VM 19.3-19.28, 21.3-21.19, 23.4-23.9 - Unauthenticated Improper Access Control via Oracle Net
CVSS 5.9
CVE-2025-61763
HIGH
Oracle Essbase 21.7.3.0.0 - Unauthorized Data Access and Modification via HTTP
CVSS 8.1
CVE-2025-61762
MEDIUM
Oracle PeopleSoft Enterprise FIN Payables 9.2 - Improper Access Control
CVSS 6.3
CVE-2025-61761
MEDIUM
Oracle PeopleSoft Enterprise FIN Maintenance Management 9.2 - Improper Access Control in Work Order Management
CVSS 5.4
CVE-2025-61760
HIGH
Oracle VM VirtualBox 7.1.12 and 7.2.2 - Authenticated Remote Code Execution
CVSS 7.5
CVE-2025-61758
MEDIUM
Oracle PeopleSoft Enterprise FIN IT Asset Management 9.2 - Unauthorized Data Access via HTTP
CVSS 6.5
CVE-2025-61749
LOW
Oracle Database Server 23.4-23.9 - Authenticated Unauthorized Data Manipulation in Unified Audit
CVSS 2.7
CVE-2025-61748
LOW
Oracle GraalVM and Java SE - Unauthenticated Improper Access Control
CVSS 3.7
CVE-2025-53071
MEDIUM
Oracle Applications Framework 12.2.3-12.2.14 - Authenticated Improper Access Control in Upload Attachments
CVSS 4.3
CVE-2025-53064
MEDIUM
Oracle Applications Framework 12.2.3-12.2.14 - Authenticated Unauthorized Data Manipulation in Personalization
CVSS 4.3
CVE-2025-53061
MEDIUM
Oracle PeopleSoft Enterprise PeopleTools 8.60-8.62 - Authenticated Improper Access Control in PIA Core Technology
CVSS 5.5
CVE-2025-53060
MEDIUM
Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.9.4 - Unauthenticated Improper Access Control via Web Runtime SEC
CVSS 6.1
CVE-2025-53059
MEDIUM
Oracle PeopleSoft Enterprise PeopleTools 8.60-8.62 - Unauthorized Data Access via OpenSearch Dashboards
CVSS 4.9
CVE-2025-53058
MEDIUM
Oracle Applications Manager 12.2.3-12.2.14 - Unauthenticated Improper Access Control via Application Logging Interfaces
CVSS 6.1
Details
Vulnerabilities
5,280