CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,299 vulnerabilities with CWE-284
CVE-2025-5162
MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Unrestricted File Upload via logGeneralFile Parameter
CVSS 6.3
CVE-2025-5131
MEDIUM
Tmall Demo < 2025-05-05 - Unrestricted File Upload via uploadCategoryImage Function
CVSS 4.7
CVE-2025-5130
MEDIUM
tmall_demo < 2025-05-05 - Unrestricted File Upload via uploadProductImage Function
CVSS 4.7
CVE-2025-24917
HIGH
Tenable Network Monitor <6.5.1 - Privilege Escalation
CVSS 7.8
CVE-2025-24916
HIGH
Tenable Network Monitor <6.5.1 - Privilege Escalation
CVSS 7.0
CVE-2025-3580
MEDIUM
Grafana 10.4.18-12.0.1 - Authenticated Server Administrator Account Deletion
CVSS 5.5
CVE-2025-5108
MEDIUM
ShopXO 6.5.0 - Unrestricted File Upload via Payment Controller ZIP Handler
CVSS 6.3
CVE-2025-5059
MEDIUM
Campcodes Online Shopping Portal 1.0 - Unrestricted Upload
CVSS 4.7
CVE-2025-20242
MEDIUM
Cisco Unified Contact Center Enterprise (CCE) - Info Disclosure
CVSS 6.5
CVE-2025-22157
HIGH
Jira Core/JSM DC/Server <10.6 - Privilege Escalation
CVSS 8.8
CVE-2025-4980
MEDIUM
Netgear DGND3700 1.1.00.15_1.00.15NA - Information Disclosure via currentsetting.htm
CVSS 5.3
CVE-2025-4977
MEDIUM
Netgear DGND3700 1.1.00.15_1.00.15NA - Information Disclosure in BRS_top.html
CVSS 5.3
CVE-2025-28371
MEDIUM
EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 - Incorrect Access Control via Password Change Function
CVSS 6.5
CVE-2025-4926
MEDIUM
PHPGurukul Car Rental Project 1.0 - Unrestricted File Upload via img1/img2/img3/img4/img5 Parameters
CVSS 4.7
CVE-2025-4923
HIGH
SourceCodester Client Database Management System 1.0 - Unrestricted File Upload via uploaded_file_cancelled Argument
CVSS 7.3
CVE-2025-23164
MEDIUM
Unifi Protect <5.3.41 - Info Disclosure
CVSS 4.4
CVE-2025-4904
MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure in /H5/webgl.data
CVSS 5.3
CVE-2025-4902
MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via versionupdate.data
CVSS 5.3
CVE-2025-4901
MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via state_view.data Endpoint
CVSS 4.3
CVE-2025-47794
LOW
Nextcloud Server 26.0.0-26.0.13.13, 29.0.0-29.0.13 - Unauthenticated Temporary File Access and Symlink Attack
CVSS 2.6
CVE-2025-47792
MEDIUM
Nextcloud Desktop < 3.15.0 - Unauthenticated Improper Access Control via Socket API
CVSS 5.0
CVE-2025-2306
MEDIUM
SYNCPILOT LIVE CONTRACT 3-5.4.11, 5.5-5.5.3, 5.6-5.6.2 - Unauthenticated Sensitive Document Download via UUIDv4
CVSS 5.9
CVE-2025-4768
MEDIUM
feng_ha_ha/megagao ssm-erp & production_ssm 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2025-4753
MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via /login.data
CVSS 5.3
CVE-2025-4752
MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via /install_base.data
CVSS 5.3
Details
Vulnerabilities
5,299