CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,299 vulnerabilities with CWE-284
CVE-2025-5162 MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Unrestricted File Upload via logGeneralFile Parameter
CVSS 6.3
CVE-2025-5131 MEDIUM
Tmall Demo < 2025-05-05 - Unrestricted File Upload via uploadCategoryImage Function
CVSS 4.7
CVE-2025-5130 MEDIUM
tmall_demo < 2025-05-05 - Unrestricted File Upload via uploadProductImage Function
CVSS 4.7
CVE-2025-24917 HIGH
Tenable Network Monitor <6.5.1 - Privilege Escalation
CVSS 7.8
CVE-2025-24916 HIGH
Tenable Network Monitor <6.5.1 - Privilege Escalation
CVSS 7.0
CVE-2025-3580 MEDIUM
Grafana 10.4.18-12.0.1 - Authenticated Server Administrator Account Deletion
CVSS 5.5
CVE-2025-5108 MEDIUM
ShopXO 6.5.0 - Unrestricted File Upload via Payment Controller ZIP Handler
CVSS 6.3
CVE-2025-5059 MEDIUM
Campcodes Online Shopping Portal 1.0 - Unrestricted Upload
CVSS 4.7
CVE-2025-20242 MEDIUM
Cisco Unified Contact Center Enterprise (CCE) - Info Disclosure
CVSS 6.5
CVE-2025-22157 HIGH
Jira Core/JSM DC/Server <10.6 - Privilege Escalation
CVSS 8.8
CVE-2025-4980 MEDIUM
Netgear DGND3700 1.1.00.15_1.00.15NA - Information Disclosure via currentsetting.htm
CVSS 5.3
CVE-2025-4977 MEDIUM
Netgear DGND3700 1.1.00.15_1.00.15NA - Information Disclosure in BRS_top.html
CVSS 5.3
CVE-2025-28371 MEDIUM
EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 - Incorrect Access Control via Password Change Function
CVSS 6.5
CVE-2025-4926 MEDIUM
PHPGurukul Car Rental Project 1.0 - Unrestricted File Upload via img1/img2/img3/img4/img5 Parameters
CVSS 4.7
CVE-2025-4923 HIGH
SourceCodester Client Database Management System 1.0 - Unrestricted File Upload via uploaded_file_cancelled Argument
CVSS 7.3
CVE-2025-23164 MEDIUM
Unifi Protect <5.3.41 - Info Disclosure
CVSS 4.4
CVE-2025-4904 MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure in /H5/webgl.data
CVSS 5.3
CVE-2025-4902 MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via versionupdate.data
CVSS 5.3
CVE-2025-4901 MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via state_view.data Endpoint
CVSS 4.3
CVE-2025-47794 LOW
Nextcloud Server 26.0.0-26.0.13.13, 29.0.0-29.0.13 - Unauthenticated Temporary File Access and Symlink Attack
CVSS 2.6
CVE-2025-47792 MEDIUM
Nextcloud Desktop < 3.15.0 - Unauthenticated Improper Access Control via Socket API
CVSS 5.0
CVE-2025-2306 MEDIUM
SYNCPILOT LIVE CONTRACT 3-5.4.11, 5.5-5.5.3, 5.6-5.6.2 - Unauthenticated Sensitive Document Download via UUIDv4
CVSS 5.9
CVE-2025-4768 MEDIUM
feng_ha_ha/megagao ssm-erp & production_ssm 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-4753 MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via /login.data
CVSS 5.3
CVE-2025-4752 MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via /install_base.data
CVSS 5.3
Details
Vulnerabilities 5,299