CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,289 vulnerabilities with CWE-284
CVE-2025-29514
CRITICAL
D-Link DSL-7740C Firmware - Unauthenticated Configuration File Download via config.xgi
CVSS 9.8
CVE-2025-9406
MEDIUM
xuhuisheng lemon <1.13.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-9400
MEDIUM
YiFang CMS <2.0.5 - Unrestricted Upload
CVSS 6.3
CVE-2025-9398
MEDIUM
YiFang CMS <2.0.5 - Info Disclosure
CVSS 5.3
CVE-2025-9397
MEDIUM
givanz Vvveb <1.0.7.2 - Unrestricted Upload
CVSS 6.3
CVE-2025-9381
LOW
FNKvision Y215 CCTV Camera - Info Disclosure
CVSS 1.6
CVE-2025-55630
HIGH
Reolink Smart 2k+ Plug-in Wi-fi Video Doorbell With Chime Firmware - Improper Access Control
CVSS 7.3
CVE-2025-55626
MEDIUM
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime <3.0.0.46...
CVSS 5.3
CVE-2025-55741
HIGH
UnoPim < 0.3.1 - Unauthenticated Improper Access Control via Mass-Delete Endpoint
CVSS 8.1
CVE-2025-53763
CRITICAL
Azure Databricks - Privilege Escalation
CVSS 9.8
CVE-2025-7051
HIGH
n-able n-central < 2025.2 - Authenticated Arbitrary Syslog Configuration Modification
CVSS 8.3
CVE-2025-55371
MEDIUM
jshERP 3.5 - Unauthenticated Information Disclosure via PersonController getAllList Method
CVSS 5.3
CVE-2025-55368
HIGH
jshERP 3.5 - Unauthenticated Arbitrary Supplier Status Modification via RoleController
CVSS 8.8
CVE-2025-55367
MEDIUM
jshERP 3.5 - Unauthenticated Arbitrary Supplier Status Modification via SupplierController
CVSS 5.3
CVE-2025-55366
MEDIUM
jshERP 3.5 - Improper Access Control in UserController
CVSS 5.3
CVE-2025-9296
MEDIUM
Emlog Pro <2.5.18 - Unrestricted Upload
CVSS 4.7
CVE-2025-27215
HIGH
UniFi Connect Display Cast <1.10.7 - Improper Access Control
CVSS 8.1
CVE-2025-9240
MEDIUM
elunez eladmin <2.7 - Info Disclosure
CVSS 4.3
CVE-2025-28041
HIGH
itranswarp < 2.19 - Unauthenticated Improper Access Control in doFilter Function
CVSS 8.6
CVE-2025-20131
MEDIUM
Cisco Identity Services Engine Software < 3.1.0 p5 and < 3.2.0 - Authenticated Arbitrary File Upload via GUI
CVSS 4.9
CVE-2025-9153
MEDIUM
Online Tour and Travel Management System 1.0 - Unrestricted File Upload via Travellers Photo Parameter
CVSS 6.3
CVE-2025-51539
MEDIUM
ezged3 3.5.0-3.5.72.27183 - Unauthenticated Arbitrary File Read via Path Traversal
CVSS 5.3
CVE-2025-50434
MEDIUM
Appian Enterprise Business Process Management <25.3 - Info Disclosure
CVSS 5.3
CVE-2025-51529
MEDIUM
Cookies and Content Security Policy < 2.29 - Denial of Service via Unlimited Database Write Operations
CVSS 5.3
CVE-2025-50897
MEDIUM
riscv-boom SonicBOOM 1.2 - Memory Corruption
CVSS 4.3
Details
Vulnerabilities
5,289