CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,289 vulnerabilities with CWE-284
CVE-2025-29514 CRITICAL
D-Link DSL-7740C Firmware - Unauthenticated Configuration File Download via config.xgi
CVSS 9.8
CVE-2025-9406 MEDIUM
xuhuisheng lemon <1.13.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-9400 MEDIUM
YiFang CMS <2.0.5 - Unrestricted Upload
CVSS 6.3
CVE-2025-9398 MEDIUM
YiFang CMS <2.0.5 - Info Disclosure
CVSS 5.3
CVE-2025-9397 MEDIUM
givanz Vvveb <1.0.7.2 - Unrestricted Upload
CVSS 6.3
CVE-2025-9381 LOW
FNKvision Y215 CCTV Camera - Info Disclosure
CVSS 1.6
CVE-2025-55630 HIGH
Reolink Smart 2k+ Plug-in Wi-fi Video Doorbell With Chime Firmware - Improper Access Control
CVSS 7.3
CVE-2025-55626 MEDIUM
Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime <3.0.0.46...
CVSS 5.3
CVE-2025-55741 HIGH
UnoPim < 0.3.1 - Unauthenticated Improper Access Control via Mass-Delete Endpoint
CVSS 8.1
CVE-2025-53763 CRITICAL
Azure Databricks - Privilege Escalation
CVSS 9.8
CVE-2025-7051 HIGH
n-able n-central < 2025.2 - Authenticated Arbitrary Syslog Configuration Modification
CVSS 8.3
CVE-2025-55371 MEDIUM
jshERP 3.5 - Unauthenticated Information Disclosure via PersonController getAllList Method
CVSS 5.3
CVE-2025-55368 HIGH
jshERP 3.5 - Unauthenticated Arbitrary Supplier Status Modification via RoleController
CVSS 8.8
CVE-2025-55367 MEDIUM
jshERP 3.5 - Unauthenticated Arbitrary Supplier Status Modification via SupplierController
CVSS 5.3
CVE-2025-55366 MEDIUM
jshERP 3.5 - Improper Access Control in UserController
CVSS 5.3
CVE-2025-9296 MEDIUM
Emlog Pro <2.5.18 - Unrestricted Upload
CVSS 4.7
CVE-2025-27215 HIGH
UniFi Connect Display Cast <1.10.7 - Improper Access Control
CVSS 8.1
CVE-2025-9240 MEDIUM
elunez eladmin <2.7 - Info Disclosure
CVSS 4.3
CVE-2025-28041 HIGH
itranswarp < 2.19 - Unauthenticated Improper Access Control in doFilter Function
CVSS 8.6
CVE-2025-20131 MEDIUM
Cisco Identity Services Engine Software < 3.1.0 p5 and < 3.2.0 - Authenticated Arbitrary File Upload via GUI
CVSS 4.9
CVE-2025-9153 MEDIUM
Online Tour and Travel Management System 1.0 - Unrestricted File Upload via Travellers Photo Parameter
CVSS 6.3
CVE-2025-51539 MEDIUM
ezged3 3.5.0-3.5.72.27183 - Unauthenticated Arbitrary File Read via Path Traversal
CVSS 5.3
CVE-2025-50434 MEDIUM
Appian Enterprise Business Process Management <25.3 - Info Disclosure
CVSS 5.3
CVE-2025-51529 MEDIUM
Cookies and Content Security Policy < 2.29 - Denial of Service via Unlimited Database Write Operations
CVSS 5.3
CVE-2025-50897 MEDIUM
riscv-boom SonicBOOM 1.2 - Memory Corruption
CVSS 4.3
Details
Vulnerabilities 5,289