CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2025-20223
MEDIUM
Cisco Catalyst Center - Info Disclosure
CVSS 4.7
CVE-2025-20190
MEDIUM
Cisco IOS XE Wireless Controller Software - Privilege Escalation
CVSS 6.5
CVE-2025-20137
MEDIUM
Cisco Catalyst 1000/2960L - Auth Bypass
CVSS 4.7
CVE-2025-29448
HIGH
Easy!Appointments 1.5.1 - Unauthenticated Denial of Service via Excessive Booking Duration
CVSS 7.5
CVE-2025-46816
CRITICAL
goshs 0.3.4-1.0.4 - Unauthenticated Remote Code Execution via WebSocket Command Injection
CVSS 9.4
CVE-2025-21470
HIGH
Qualcomm AQT1000 Firmware - Memory Corruption via Image Encoding IOCTL Parameter
CVSS 7.8
CVE-2025-21469
HIGH
Qualcomm FastConnect and Snapdragon Firmware - Memory Corruption via IOCTL Call with Zero-Length Buffer
CVSS 7.8
CVE-2025-4333
MEDIUM
feng_ha_ha/megagao ssm-erp & production_ssm <0.0.1 - Unrestricted U...
CVSS 6.3
CVE-2025-46589
MEDIUM
HarmonyOS - Unauthorized Access in App Lock Module
CVSS 4.4
CVE-2025-46588
MEDIUM
HarmonyOS - Unauthorized Access in App Lock Module
CVSS 4.4
CVE-2025-4310
MEDIUM
itsourcecode Content Management System 1.0 - Unrestricted File Upload via Cover Image Argument
CVSS 4.7
CVE-2025-4305
MEDIUM
Kefaming mayi <1.3.9 - Unrestricted Upload
CVSS 6.3
CVE-2025-4291
MEDIUM
ideacms < 1.6 - Unrestricted File Upload via saveUpload Function
CVSS 6.3
CVE-2025-45618
MEDIUM
jeeweb-mybatis-springboot v0.0.1.RELEASE - Improper Access Control in /admin/sys/datasource/ajaxList
CVSS 6.5
CVE-2025-45617
HIGH
production_ssm v0.0.1-SNAPSHOT - Improper Access Control in /user/list
CVSS 7.5
CVE-2025-45616
CRITICAL
baidu brcc < 1.2.0 - Unauthenticated Privilege Escalation via Admin API
CVSS 9.8
CVE-2025-45615
CRITICAL
yaoqishan v0.0.1-SNAPSHOT - Incorrect Access Control in Admin API
CVSS 9.8
CVE-2025-45614
HIGH
One v1.0 - Improper Access Control in /api/user/manager
CVSS 7.5
CVE-2025-45613
HIGH
shiro-action < 0.6 - Improper Access Control in /user/list Endpoint
CVSS 7.5
CVE-2025-45612
CRITICAL
xmall < 1.1 - Unauthenticated Authentication Bypass via /index GET Request
CVSS 9.8
CVE-2025-45611
CRITICAL
hope-boot 1.0.0 - Unauthenticated Authentication Bypass via /user/edit/ GET Request
CVSS 9.8
CVE-2025-45610
HIGH
passjava < 3.0.0 - Improper Access Control in /scheduleLog/info/1 Endpoint
CVSS 7.5
CVE-2025-45609
HIGH
ke/kob 1.0.0-SNAPSHOT - Improper Access Control in doFilter Function
CVSS 7.5
CVE-2025-45608
HIGH
Xinguan < 0.0.1-snapshot - Improper Access Control in User List API
CVSS 7.5
CVE-2025-4051
MEDIUM
Google Chrome < 136.0.7103.59 - Discretionary Access Control Bypass via DevTools
CVSS 6.3
Details
Vulnerabilities
5,300