CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2025-20223 MEDIUM
Cisco Catalyst Center - Info Disclosure
CVSS 4.7
CVE-2025-20190 MEDIUM
Cisco IOS XE Wireless Controller Software - Privilege Escalation
CVSS 6.5
CVE-2025-20137 MEDIUM
Cisco Catalyst 1000/2960L - Auth Bypass
CVSS 4.7
CVE-2025-29448 HIGH
Easy!Appointments 1.5.1 - Unauthenticated Denial of Service via Excessive Booking Duration
CVSS 7.5
CVE-2025-46816 CRITICAL
goshs 0.3.4-1.0.4 - Unauthenticated Remote Code Execution via WebSocket Command Injection
CVSS 9.4
CVE-2025-21470 HIGH
Qualcomm AQT1000 Firmware - Memory Corruption via Image Encoding IOCTL Parameter
CVSS 7.8
CVE-2025-21469 HIGH
Qualcomm FastConnect and Snapdragon Firmware - Memory Corruption via IOCTL Call with Zero-Length Buffer
CVSS 7.8
CVE-2025-4333 MEDIUM
feng_ha_ha/megagao ssm-erp & production_ssm <0.0.1 - Unrestricted U...
CVSS 6.3
CVE-2025-46589 MEDIUM
HarmonyOS - Unauthorized Access in App Lock Module
CVSS 4.4
CVE-2025-46588 MEDIUM
HarmonyOS - Unauthorized Access in App Lock Module
CVSS 4.4
CVE-2025-4310 MEDIUM
itsourcecode Content Management System 1.0 - Unrestricted File Upload via Cover Image Argument
CVSS 4.7
CVE-2025-4305 MEDIUM
Kefaming mayi <1.3.9 - Unrestricted Upload
CVSS 6.3
CVE-2025-4291 MEDIUM
ideacms < 1.6 - Unrestricted File Upload via saveUpload Function
CVSS 6.3
CVE-2025-45618 MEDIUM
jeeweb-mybatis-springboot v0.0.1.RELEASE - Improper Access Control in /admin/sys/datasource/ajaxList
CVSS 6.5
CVE-2025-45617 HIGH
production_ssm v0.0.1-SNAPSHOT - Improper Access Control in /user/list
CVSS 7.5
CVE-2025-45616 CRITICAL
baidu brcc < 1.2.0 - Unauthenticated Privilege Escalation via Admin API
CVSS 9.8
CVE-2025-45615 CRITICAL
yaoqishan v0.0.1-SNAPSHOT - Incorrect Access Control in Admin API
CVSS 9.8
CVE-2025-45614 HIGH
One v1.0 - Improper Access Control in /api/user/manager
CVSS 7.5
CVE-2025-45613 HIGH
shiro-action < 0.6 - Improper Access Control in /user/list Endpoint
CVSS 7.5
CVE-2025-45612 CRITICAL
xmall < 1.1 - Unauthenticated Authentication Bypass via /index GET Request
CVSS 9.8
CVE-2025-45611 CRITICAL
hope-boot 1.0.0 - Unauthenticated Authentication Bypass via /user/edit/ GET Request
CVSS 9.8
CVE-2025-45610 HIGH
passjava < 3.0.0 - Improper Access Control in /scheduleLog/info/1 Endpoint
CVSS 7.5
CVE-2025-45609 HIGH
ke/kob 1.0.0-SNAPSHOT - Improper Access Control in doFilter Function
CVSS 7.5
CVE-2025-45608 HIGH
Xinguan < 0.0.1-snapshot - Improper Access Control in User List API
CVSS 7.5
CVE-2025-4051 MEDIUM
Google Chrome < 136.0.7103.59 - Discretionary Access Control Bypass via DevTools
CVSS 6.3
Details
Vulnerabilities 5,300