CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,283 vulnerabilities with CWE-284
CVE-2025-61777 CRITICAL
FlagForge 2.0.0-2.3.1 - Unauthenticated Improper Access Control in Badge Template Endpoints
CVSS 9.4
CVE-2025-57247 CRITICAL
BATBToken <0.8.26+commit.8a97fa7 - Privilege Escalation
CVSS 9.1
CVE-2025-11320 MEDIUM
zhuimengshaonian wisdom-education <1.0.4 - Unrestricted Upload
CVSS 6.3
CVE-2025-11318 HIGH
Tipray Data Leakage Prevention System 1.0 - Unrestricted Upload
CVSS 7.3
CVE-2025-11281 MEDIUM
Frappe LMS 2.35.0 - Info Disclosure
CVSS 5.0
CVE-2025-59943 HIGH
phpMyFAQ < 4.0.13 - Improper Access Control via Duplicate Email Registration
CVSS 8.1
CVE-2025-59951 CRITICAL
Termix < 1.6.0 - Unauthenticated Sensitive Information Exposure via /ssh/db/host/internal Endpoint
CVSS 9.1
CVE-2025-58055 MEDIUM
Discourse < 3.5.1 - Authenticated Improper Access Control via AI Suggestion Endpoint Topic ID Manipulation
CVSS 4.3
CVE-2025-20366 MEDIUM
Splunk <9.4.4, <9.3.6, <9.2.8 - Info Disclosure
CVSS 6.5
CVE-2025-10847 HIGH
DX Unified Infrastructure Management < - Command Injection
CVE-2025-55797 MEDIUM
FormCMS < 0.5.5 - Unauthenticated Improper Access Control via Schema History Endpoint
CVSS 6.5
CVE-2025-11163 MEDIUM
SmartCrawl SEO checker - Info Disclosure
CVSS 4.3
CVE-2025-54875 CRITICAL
FreshRSS 1.16.0-1.26.3 - Unauthenticated Privilege Escalation via Hidden Admin Field
CVSS 9.8
CVE-2025-57266 CRITICAL
ThriveX Blogging Framework <3.1.3 - Info Disclosure
CVSS 9.8
CVE-2025-54591 HIGH
FreshRSS < 1.27.0 - Unauthenticated Information Disclosure via Tag/Feed Endpoints
CVSS 7.5
CVE-2025-57197 MEDIUM
Payeer Android 2.5.0 - Privilege Escalation
CVSS 6.0
CVE-2025-55795 LOW
openml/openml.org v2.0.20241110 - Open Redirect
CVSS 3.5
CVE-2025-36351 MEDIUM
IBM License Metric Tool 9.2.0-9.2.40 - Authenticated Access Control Bypass in REST API
CVSS 4.3
CVE-2025-57428 MEDIUM
Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.201...
CVSS 6.5
CVE-2025-11136 MEDIUM
YiFang CMS <2.0.2 - Unrestricted Upload
CVSS 4.7
CVE-2025-11103 MEDIUM
Projectworlds Online Tours and Travels 1.0 - Unrestricted Upload
CVSS 4.7
CVE-2025-11078 MEDIUM
itsourcecode Open Source Job Portal 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-59932 HIGH
flagforge 2.0.0-2.3.0 - Unauthenticated Improper Access Control in /api/resources Endpoint
CVSS 8.6
CVE-2025-11028 MEDIUM
givanz Vvveb <1.0.7.2 - Info Disclosure
CVSS 5.3
CVE-2025-11026 LOW
givanz Vvveb <1.0.7.2 - Info Disclosure
CVSS 3.5
Details
Vulnerabilities 5,283