CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,299 vulnerabilities with CWE-284
CVE-2025-5429
MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Plugins Page
CVSS 6.3
CVE-2025-5428
MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Error Logs Page
CVSS 6.3
CVE-2025-5427
MEDIUM
juzaweb CMS 3.4-3.4.2 - Improper Access Control in Permalinks Page
CVSS 6.3
CVE-2025-5426
MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Menu Page
CVSS 6.3
CVE-2025-5425
MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Theme Editor Page
CVSS 6.3
CVE-2025-5424
MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in Media Page
CVSS 6.3
CVE-2025-5423
MEDIUM
juzaweb CMS < 3.4.2 - Improper Access Control in General Setting Page
CVSS 6.3
CVE-2025-5422
MEDIUM
juzaweb CMS 3.4-3.4.2 - Improper Access Control in Email Logs Page
CVSS 4.3
CVE-2025-5421
MEDIUM
juzaweb CMS 3.4-3.4.2 - Improper Access Control in Plugin Editor Page
CVSS 6.3
CVE-2025-5409
HIGH
Mist Community Edition < 4.7.2 - Improper Access Control in API Token Handler
CVSS 7.3
CVE-2025-5406
MEDIUM
chaitak-gorai/blogbook < 2021-11-22 - Unrestricted File Upload via posts.php image Parameter
CVSS 6.3
CVE-2025-5390
MEDIUM
JeeWMS < 2025-05-04 - Improper Access Control in File Handler
CVSS 6.3
CVE-2025-5389
MEDIUM
JeeWMS < 2025-05-04 - Improper Access Control in File Handler
CVSS 6.3
CVE-2025-5387
MEDIUM
JeeWMS < 2025-05-04 - Improper Access Control in File Handler
CVSS 6.3
CVE-2025-4433
HIGH
Devolutions Server < 2025.1.9.0 - Privilege Escalation via User Group Management
CVSS 8.8
CVE-2025-4431
MEDIUM
Featured Image Plus <= 1.6.4 - Authenticated Data Modification via fip_save_attach_featured
CVSS 4.3
CVE-2025-44619
CRITICAL
Tinxy WiFi Lock Controller v1 RF - Unauthenticated Network Access via Open Wi-Fi Configuration
CVSS 9.1
CVE-2025-27702
MEDIUM
Absolute Secure Access < 13.54 - Authenticated Permission Bypass in Management Console
CVSS 4.9
CVE-2025-45343
CRITICAL
Tenda W18E v.16.01.0.11 - Remote Code Execution via Account Module Editing
CVSS 9.8
CVE-2025-48734
HIGH
Apache Commons <2.0.0 - Info Disclosure
CVSS 8.8
CVE-2025-5299
HIGH
Client Database Management System 1.0 - Unrestricted File Upload via uploaded_file_cancelled Parameter
CVSS 7.3
CVE-2025-5184
MEDIUM
Summer Pearl Group Vacation Rental Management Platform < 1.0.2 - Information Disclosure via HTTP Response Header
CVSS 4.3
CVE-2025-5178
MEDIUM
Realce Tecnologia Queue Ticket Kiosk < 2025-05-17 - Unrestricted File Upload via Image File Handler
CVSS 6.3
CVE-2025-5171
MEDIUM
llisoft MTA Maita Training System 4.5 - Unrestricted File Upload via OpenController File Download Function
CVSS 6.3
CVE-2025-5163
MEDIUM
yangshare warehouse_management_system 1.0 - Improper Access Control
CVSS 5.3
Details
Vulnerabilities
5,299