CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,299 vulnerabilities with CWE-284
CVE-2025-5429 MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Plugins Page
CVSS 6.3
CVE-2025-5428 MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Error Logs Page
CVSS 6.3
CVE-2025-5427 MEDIUM
juzaweb CMS 3.4-3.4.2 - Improper Access Control in Permalinks Page
CVSS 6.3
CVE-2025-5426 MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Menu Page
CVSS 6.3
CVE-2025-5425 MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Theme Editor Page
CVSS 6.3
CVE-2025-5424 MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Media Page
CVSS 6.3
CVE-2025-5423 MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in General Setting Page
CVSS 6.3
CVE-2025-5422 MEDIUM
juzaweb CMS 3.4-3.4.2 - Improper Access Control in Email Logs Page
CVSS 4.3
CVE-2025-5421 MEDIUM
juzaweb CMS 3.4-3.4.2 - Improper Access Control in Plugin Editor Page
CVSS 6.3
CVE-2025-5409 HIGH
Mist Community Edition < 4.7.2 - Improper Access Control in API Token Handler
CVSS 7.3
CVE-2025-5406 MEDIUM
chaitak-gorai/blogbook < 2021-11-22 - Unrestricted File Upload via posts.php image Parameter
CVSS 6.3
CVE-2025-5390 MEDIUM
JeeWMS < 2025-05-04 - Improper Access Control in File Handler
CVSS 6.3
CVE-2025-5389 MEDIUM
JeeWMS < 2025-05-04 - Improper Access Control in File Handler
CVSS 6.3
CVE-2025-5387 MEDIUM
JeeWMS < 2025-05-04 - Improper Access Control in File Handler
CVSS 6.3
CVE-2025-4433 HIGH
Devolutions Server < 2025.1.9.0 - Privilege Escalation via User Group Management
CVSS 8.8
CVE-2025-4431 MEDIUM
Featured Image Plus <= 1.6.4 - Authenticated Data Modification via fip_save_attach_featured
CVSS 4.3
CVE-2025-44619 CRITICAL
Tinxy WiFi Lock Controller v1 RF - Unauthenticated Network Access via Open Wi-Fi Configuration
CVSS 9.1
CVE-2025-27702 MEDIUM
Absolute Secure Access < 13.54 - Authenticated Permission Bypass in Management Console
CVSS 4.9
CVE-2025-45343 CRITICAL
Tenda W18E v.16.01.0.11 - Remote Code Execution via Account Module Editing
CVSS 9.8
CVE-2025-48734 HIGH
Apache Commons <2.0.0 - Info Disclosure
CVSS 8.8
CVE-2025-5299 HIGH
Client Database Management System 1.0 - Unrestricted File Upload via uploaded_file_cancelled Parameter
CVSS 7.3
CVE-2025-5184 MEDIUM
Summer Pearl Group Vacation Rental Management Platform < 1.0.2 - Information Disclosure via HTTP Response Header
CVSS 4.3
CVE-2025-5178 MEDIUM
Realce Tecnologia Queue Ticket Kiosk < 2025-05-17 - Unrestricted File Upload via Image File Handler
CVSS 6.3
CVE-2025-5171 MEDIUM
llisoft MTA Maita Training System 4.5 - Unrestricted File Upload via OpenController File Download Function
CVSS 6.3
CVE-2025-5163 MEDIUM
yangshare warehouse_management_system 1.0 - Improper Access Control
CVSS 5.3
Details
Vulnerabilities 5,299