CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,289 vulnerabilities with CWE-284
CVE-2025-10608
MEDIUM
Portabilis i-educar < 2.10.0 - Incorrect Privilege Assignment in Enrollment History Endpoint
CVSS 6.3
CVE-2025-10607
MEDIUM
Portabilis i-educar < 2.10.0 - Exposure of Sensitive Information via /module/Avaliacao/diarioApi
CVSS 4.3
CVE-2025-10600
HIGH
SourceCodester Online Exam Form Submission 1.0 - Unrestricted File Upload via register.php img Argument
CVSS 7.3
CVE-2025-37131
MEDIUM
EdgeConnect SD-WAN ECOS - Privilege Escalation
CVSS 4.9
CVE-2025-37125
HIGH
HPE Aruba Networking EdgeConnect OS - Auth Bypass
CVSS 7.5
CVE-2025-54391
CRITICAL
Zimbra Collaboration - Authenticated Two-Factor Authentication Bypass via EnableTwoFactorAuthRequest SOAP Endpoint
CVSS 9.1
CVE-2025-59333
HIGH
@executeautomation/database-server < 1.1.0 - Improper Access Control in Read-Only Mode
CVSS 8.1
CVE-2025-43371
HIGH
Xcode < 26.0 - Sandbox Escape via Improved Checks Bypass
CVSS 8.2
CVE-2025-43369
MEDIUM
macOS < 26 - Unprotected User Data Exposure via Symlink Handling
CVSS 5.5
CVE-2025-43340
HIGH
macOS Tahoe 26 - Privilege Escalation
CVSS 7.8
CVE-2025-43337
MEDIUM
macOS < 15.7.2 and < 26.0 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 5.5
CVE-2025-43332
MEDIUM
macOS Sonoma <14.8 - Privilege Escalation
CVSS 5.2
CVE-2025-43328
LOW
macOS < 26 - Unprotected User Data Exposure via Permissions Issue
CVSS 3.3
CVE-2025-43325
MEDIUM
macOS < 26 - Unprotected User Data Exposure via Sandbox Restriction Bypass
CVSS 5.5
CVE-2025-43321
MEDIUM
macOS <Sonoma 14.8-Sequioia 15.7 - Info Disclosure
CVSS 5.5
CVE-2025-43319
MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure
CVSS 5.5
CVE-2025-43317
MEDIUM
Apple VisionOS-IPadOS-watchOS <26 - Info Disclosure
CVSS 5.5
CVE-2025-43315
MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure
CVSS 5.5
CVE-2025-43308
MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure via Improper Access Control
CVSS 5.3
CVE-2025-43305
MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure via Logic Issue
CVSS 5.5
CVE-2025-43294
LOW
macOS < 26 - Unprotected User Data Exposure via Environment Variable Handling
CVSS 3.3
CVE-2025-43291
MEDIUM
macOS Sonoma <14.8 - Info Disclosure
CVSS 5.5
CVE-2025-43285
MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure via Permissions Issue
CVSS 5.5
CVE-2025-43263
HIGH
Xcode < 26.0 - Improper Access Control
CVSS 7.1
CVE-2025-43208
MEDIUM
macOS < 26 - Unprotected User Data Exposure via Location Information Access
CVSS 5.5
Details
Vulnerabilities
5,289