CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,289 vulnerabilities with CWE-284
CVE-2025-10608 MEDIUM
Portabilis i-educar < 2.10.0 - Incorrect Privilege Assignment in Enrollment History Endpoint
CVSS 6.3
CVE-2025-10607 MEDIUM
Portabilis i-educar < 2.10.0 - Exposure of Sensitive Information via /module/Avaliacao/diarioApi
CVSS 4.3
CVE-2025-10600 HIGH
SourceCodester Online Exam Form Submission 1.0 - Unrestricted File Upload via register.php img Argument
CVSS 7.3
CVE-2025-37131 MEDIUM
EdgeConnect SD-WAN ECOS - Privilege Escalation
CVSS 4.9
CVE-2025-37125 HIGH
HPE Aruba Networking EdgeConnect OS - Auth Bypass
CVSS 7.5
CVE-2025-54391 CRITICAL
Zimbra Collaboration - Authenticated Two-Factor Authentication Bypass via EnableTwoFactorAuthRequest SOAP Endpoint
CVSS 9.1
CVE-2025-59333 HIGH
@executeautomation/database-server < 1.1.0 - Improper Access Control in Read-Only Mode
CVSS 8.1
CVE-2025-43371 HIGH
Xcode < 26.0 - Sandbox Escape via Improved Checks Bypass
CVSS 8.2
CVE-2025-43369 MEDIUM
macOS < 26 - Unprotected User Data Exposure via Symlink Handling
CVSS 5.5
CVE-2025-43340 HIGH
macOS Tahoe 26 - Privilege Escalation
CVSS 7.8
CVE-2025-43337 MEDIUM
macOS < 15.7.2 and < 26.0 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 5.5
CVE-2025-43332 MEDIUM
macOS Sonoma <14.8 - Privilege Escalation
CVSS 5.2
CVE-2025-43328 LOW
macOS < 26 - Unprotected User Data Exposure via Permissions Issue
CVSS 3.3
CVE-2025-43325 MEDIUM
macOS < 26 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 5.5
CVE-2025-43321 MEDIUM
macOS <Sonoma 14.8-Sequioia 15.7 - Info Disclosure
CVSS 5.5
CVE-2025-43319 MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure
CVSS 5.5
CVE-2025-43317 MEDIUM
Apple VisionOS-IPadOS-watchOS <26 - Info Disclosure
CVSS 5.5
CVE-2025-43315 MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure
CVSS 5.5
CVE-2025-43308 MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure via Improper Access Control
CVSS 5.3
CVE-2025-43305 MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure via Logic Issue
CVSS 5.5
CVE-2025-43294 LOW
macOS < 26 - Unprotected User Data Exposure via Environment Variable Handling
CVSS 3.3
CVE-2025-43291 MEDIUM
macOS Sonoma <14.8 - Info Disclosure
CVSS 5.5
CVE-2025-43285 MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure via Permissions Issue
CVSS 5.5
CVE-2025-43263 HIGH
Xcode < 26.0 - Improper Access Control
CVSS 7.1
CVE-2025-43208 MEDIUM
macOS < 26 - Unprotected User Data Exposure via Location Information Access
CVSS 5.5
Details
Vulnerabilities 5,289