CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2025-4752
MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via /install_base.data
CVSS 5.3
CVE-2025-4751
MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure via /index.data
CVSS 5.3
CVE-2025-4750
MEDIUM
D-Link DI-7003GV2 24.04.18D1 R(68125) - Information Disclosure in Configuration Handler
CVSS 5.3
CVE-2025-4735
MEDIUM
Campcodes Sales and Inventory System 1.0 - Unrestricted File Upload via Picture Parameter in product.php
CVSS 6.3
CVE-2025-47161
HIGH
Microsoft Defender for Endpoint < 101.25022.0002 - Privilege Escalation
CVSS 7.8
CVE-2025-47884
CRITICAL
Jenkins OpenID Connect Provider Plugin < 96.vee8ed882ec4d - Impersonation via Environment Variable Override
CVSS 9.1
CVE-2025-43563
CRITICAL
ColdFusion 2025.1 2023.13 2021.19 and earlier - Authenticated Arbitrary File System Read
CVSS 9.1
CVE-2025-22844
MEDIUM
Intel(R) Tiber Edge Platform - Info Disclosure
CVSS 4.3
CVE-2025-20100
HIGH
Intel(R) Xeon(R) 6 - Privilege Escalation
CVSS 7.5
CVE-2025-20076
MEDIUM
Intel(R) Tiber Edge Platform - Privilege Escalation
CVSS 5.0
CVE-2025-20052
HIGH
Intel(R) Graphics software - Authenticated Denial of Service via Local Access
CVSS 7.3
CVE-2025-29973
HIGH
Azure File Sync - Privilege Escalation
CVSS 7.0
CVE-2025-31260
MEDIUM
macOS < 15.5 - Unprotected User Data Exposure via Permissions Issue
CVSS 5.5
CVE-2025-31258
MEDIUM
macOS < 15.5 - Sandbox Escape via Vulnerable Code Removal
CVSS 6.5
CVE-2025-31247
HIGH
macOS < 13.7.6, < 14.7.6, < 15.5 - Unprotected File System Access via Logic Issue
CVSS 7.5
CVE-2025-31232
HIGH
macOS < 13.7.6, < 14.7.6, < 15.5 - Unprotected User Data Exposure via Sandbox Bypass
CVSS 7.1
CVE-2025-31212
MEDIUM
iPadOS < 18.5 - Unauthorized Sensitive Data Access
CVSS 5.5
CVE-2025-31195
MEDIUM
macOS < 15.4 - Sandbox Escape via Improper Access Control
CVSS 6.3
CVE-2025-30436
CRITICAL
iPadOS < 18.4 - Improper Access Control via Siri Auto-Answer Calls
CVSS 9.1
CVE-2025-4538
MEDIUM
kkFileView 4.4.0 - Unauthenticated Arbitrary File Upload via /fileUpload Endpoint
CVSS 6.3
CVE-2025-4536
MEDIUM
Gosuncn Audio-Visual Platform 1.0 Information Disclosure via /sysmgr/user/listByPage
CVSS 5.3
CVE-2025-4535
MEDIUM
Gosuncn Audio-Visual Platform 4.0 - Configuration File Information Disclosure
CVSS 5.3
CVE-2025-28201
MEDIUM
Victure RX1800 EN_V1.0.0_r12_110933 - Unauthenticated Arbitrary Code Execution
CVSS 6.8
CVE-2025-4468
HIGH
Online Student Clearance System 1.0 - Unrestricted File Upload via userImage Parameter
CVSS 7.3
CVE-2025-33072
HIGH
msagsfeedback.azurewebsites.net - Unauthenticated Information Disclosure
CVSS 8.1
Details
Vulnerabilities
5,300