CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2025-3764 MEDIUM
Senior-walter Web-based Pharmacy Product Management System - Improper Access Control
CVSS 6.3
CVE-2025-3113 CRITICAL
Continuous Compliance - Info Disclosure
CVE-2025-1568 HIGH
Google ChromeOS 16063.87.0 - Remote Code Execution and Denial of Service via Gerrit Project Configuration
CVSS 8.8
CVE-2025-3675 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setL2tpServerCfg
CVSS 5.3
CVE-2025-3674 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUrlFilterRules Function
CVSS 5.3
CVE-2025-3668 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setScheduleCfg Function
CVSS 5.3
CVE-2025-3667 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUPnPCfg Function
CVSS 5.3
CVE-2025-3666 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setDdnsCfg Function
CVSS 5.3
CVE-2025-3665 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setSmartQosCfg
CVSS 5.3
CVE-2025-3664 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setWiFiEasyGuestCfg
CVSS 5.3
CVE-2025-3663 MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in Password Handler
CVSS 5.3
CVE-2025-30100 MEDIUM
Dell Alienware Command Center <6.7.37.0 - Privilege Escalation
CVSS 6.7
CVE-2025-30740 MEDIUM
Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.9.2 - Unauthorized Data Access via Web Runtime SEC
CVSS 6.5
CVE-2025-30736 HIGH
Oracle Java VM 19.3-19.26, 21.3-21.17, 23.4-23.7 - Unauthenticated Improper Access Control
CVSS 7.4
CVE-2025-30735 HIGH
Oracle PeopleSoft Enterprise CC Common Application Objects 9.2 - Improper Access Control in Page and Field Configuration
CVSS 8.1
CVE-2025-30732 MEDIUM
Oracle Application Object Library 12.2.3-12.2.14 - Unauthenticated Improper Access Control via HTTP
CVSS 6.1
CVE-2025-30731 LOW
Oracle Applications Technology Stack 12.2.3-12.2.14 - Unauthenticated Improper Access Control in Configuration
CVSS 3.6
CVE-2025-30729 MEDIUM
Oracle Communications Order and Service Management 7.4.0/7.4.1/7.5.0 - Unauthorized Data Access and Partial DoS
CVSS 5.5
CVE-2025-30728 HIGH
Oracle Configurator 12.2.3-12.2.14 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2025-30726 MEDIUM
Oracle Application Object Library 12.2.3-12.2.14 - Unauthenticated Unauthorized Data Read via HTTP
CVSS 5.3
CVE-2025-30714 MEDIUM
Oracle MySQL Connectors 9.0.0-9.2.0 - Unauthorized Data Access via Connector/Python
CVSS 4.8
CVE-2025-30713 MEDIUM
Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager 9.2 - Improper Access Control in Job Opening
CVSS 5.4
CVE-2025-30711 MEDIUM
Oracle Applications Framework 12.2.3-12.2.14 - Authenticated Improper Access Control in Attachments File Upload
CVSS 5.4
CVE-2025-30710 MEDIUM
MySQL Cluster 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Authenticated Denial of Service in NDBCluster Plugin
CVSS 4.9
CVE-2025-30709 MEDIUM
Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.9.2 - Unauthenticated Improper Access Control via Web Runtime SEC
CVSS 6.1
Details
Vulnerabilities 5,300