CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2025-2551
MEDIUM
D-Link DIR-618 and DIR-605L - Improper Access Control in /goform/formSetPortTr
CVSS 4.3
CVE-2025-2550
MEDIUM
D-Link DIR-618 and DIR-605L 2.02/3.02 - Improper Access Control in DDNS Service
CVSS 4.3
CVE-2025-2549
MEDIUM
D-Link DIR-618 and DIR-605L 2.02/3.02 - Improper Access Control via formSetPassword
CVSS 4.3
CVE-2025-2548
MEDIUM
D-Link DIR-618 and DIR-605L - Improper Access Control in formSetDomainFilter
CVSS 4.3
CVE-2025-2547
MEDIUM
D-Link DIR-618 and DIR-605L - Improper Access Control in /goform/formAdvNetwork
CVSS 4.3
CVE-2025-2546
MEDIUM
D-Link DIR-618 and DIR-605L - Improper Access Control in Firewall Service
CVSS 4.3
CVE-2025-30140
HIGH
G-Net Dashcam BB GONX - Info Disclosure
CVSS 7.5
CVE-2025-30141
HIGH
G-Net Dashcam BB GONX - Info Disclosure
CVSS 7.5
CVE-2025-30138
MEDIUM
G-Net Dashcam BB GONX - Privilege Escalation
CVSS 4.6
CVE-2025-26138
MEDIUM
Systemic Risk Value <= 2.8.0 - Unauthenticated Improper Access Control via Predictable File ID Parameter
CVSS 6.5
CVE-2025-30132
CRITICAL
IROAD Dashcam V - Improper Access Control via Unregistered Public Domain
CVSS 9.1
CVE-2025-25585
HIGH
yimioa < 2024.07.04 - Unauthenticated Administrator Password Modification via WebSecurityConfig
CVSS 7.3
CVE-2025-25500
HIGH
cosmwasm < 2.2.0 - Improper Access Control via Capability Validation Bypass
CVSS 7.5
CVE-2025-25621
MEDIUM
Unifiedtransform 2.0 - Incorrect Access Control via Teacher Attendance Endpoint
CVSS 4.3
CVE-2025-25618
LOW
Unifiedtransform 2.0 - Privilege Escalation via Incorrect Access Control
CVSS 3.3
CVE-2025-2350
MEDIUM
Iroadau Fx2 Firmware < 2025-03-08 - Improper Access Control
CVSS 6.3
CVE-2025-2348
MEDIUM
Iroadau Fx2 Firmware < 2025-03-08 - Information Disclosure
CVSS 4.3
CVE-2025-2334
MEDIUM
springboot-openai-chatgpt e84f6f5 - Improper Access Control in Chat History Handler
CVSS 5.4
CVE-2025-25225
MEDIUM
Hikashop <5.1.3 - Privilege Escalation
CVSS 6.5
CVE-2025-25598
HIGH
Inova Logic CUSTOMER MONITOR 3.1.757.1 - Privilege Escalation via Scheduled Task Executable Injection
CVSS 8.8
CVE-2025-2280
HIGH
Devolutions Server < 2024.3.6.0 - Authenticated Browser Extension Restriction Bypass
CVSS 8.1
CVE-2025-2278
MEDIUM
Devolutions Server < 2025.1.3.0 - Authenticated Improper Access Control in Temporary Access Requests
CVSS 6.5
CVE-2025-25683
MEDIUM
AlekSIS-Core <3.2.1 - Info Disclosure
CVSS 5.6
CVE-2025-20144
MEDIUM
Cisco IOS XR - Unauthenticated Access Control Bypass via Hybrid ACL Processing
CVSS 4.0
CVE-2025-2219
HIGH
LoveCards 2.1.1-2.3.2 - Unauthenticated Unrestricted File Upload via /api/upload/image
CVSS 7.3
Details
Vulnerabilities
5,300