CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2025-3764
MEDIUM
Senior-walter Web-based Pharmacy Product Management System - Improper Access Control
CVSS 6.3
CVE-2025-3113
CRITICAL
Continuous Compliance - Info Disclosure
CVE-2025-1568
HIGH
Google ChromeOS 16063.87.0 - Remote Code Execution and Denial of Service via Gerrit Project Configuration
CVSS 8.8
CVE-2025-3675
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setL2tpServerCfg
CVSS 5.3
CVE-2025-3674
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUrlFilterRules Function
CVSS 5.3
CVE-2025-3668
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setScheduleCfg Function
CVSS 5.3
CVE-2025-3667
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setUPnPCfg Function
CVSS 5.3
CVE-2025-3666
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setDdnsCfg Function
CVSS 5.3
CVE-2025-3665
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setSmartQosCfg
CVSS 5.3
CVE-2025-3664
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in setWiFiEasyGuestCfg
CVSS 5.3
CVE-2025-3663
MEDIUM
TOTOLINK A3700R 9.1.2u.5822_B20200513 - Improper Access Control in Password Handler
CVSS 5.3
CVE-2025-30100
MEDIUM
Dell Alienware Command Center <6.7.37.0 - Privilege Escalation
CVSS 6.7
CVE-2025-30740
MEDIUM
Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.9.2 - Unauthorized Data Access via Web Runtime SEC
CVSS 6.5
CVE-2025-30736
HIGH
Oracle Java VM 19.3-19.26, 21.3-21.17, 23.4-23.7 - Unauthenticated Improper Access Control
CVSS 7.4
CVE-2025-30735
HIGH
Oracle PeopleSoft Enterprise CC Common Application Objects 9.2 - Improper Access Control in Page and Field Configuration
CVSS 8.1
CVE-2025-30732
MEDIUM
Oracle Application Object Library 12.2.3-12.2.14 - Unauthenticated Improper Access Control via HTTP
CVSS 6.1
CVE-2025-30731
LOW
Oracle Applications Technology Stack 12.2.3-12.2.14 - Unauthenticated Improper Access Control in Configuration
CVSS 3.6
CVE-2025-30729
MEDIUM
Oracle Communications Order and Service Management 7.4.0/7.4.1/7.5.0 - Unauthorized Data Access and Partial DoS
CVSS 5.5
CVE-2025-30728
HIGH
Oracle Configurator 12.2.3-12.2.14 - Unauthenticated Unauthorized Data Access via HTTP
CVSS 7.5
CVE-2025-30726
MEDIUM
Oracle Application Object Library 12.2.3-12.2.14 - Unauthenticated Unauthorized Data Read via HTTP
CVSS 5.3
CVE-2025-30714
MEDIUM
Oracle MySQL Connectors 9.0.0-9.2.0 - Unauthorized Data Access via Connector/Python
CVSS 4.8
CVE-2025-30713
MEDIUM
Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager 9.2 - Improper Access Control in Job Opening
CVSS 5.4
CVE-2025-30711
MEDIUM
Oracle Applications Framework 12.2.3-12.2.14 - Authenticated Improper Access Control in Attachments File Upload
CVSS 5.4
CVE-2025-30710
MEDIUM
MySQL Cluster 8.0.0-8.0.41, 8.4.0-8.4.4, 9.0.0-9.2.0 - Authenticated Denial of Service in NDBCluster Plugin
CVSS 4.9
CVE-2025-30709
MEDIUM
Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.9.2 - Unauthenticated Improper Access Control via Web Runtime SEC
CVSS 6.1
Details
Vulnerabilities
5,300