CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2025-2551 MEDIUM
D-Link DIR-618 and DIR-605L - Improper Access Control in /goform/formSetPortTr
CVSS 4.3
CVE-2025-2550 MEDIUM
D-Link DIR-618 and DIR-605L 2.02/3.02 - Improper Access Control in DDNS Service
CVSS 4.3
CVE-2025-2549 MEDIUM
D-Link DIR-618 and DIR-605L 2.02/3.02 - Improper Access Control via formSetPassword
CVSS 4.3
CVE-2025-2548 MEDIUM
D-Link DIR-618 and DIR-605L - Improper Access Control in formSetDomainFilter
CVSS 4.3
CVE-2025-2547 MEDIUM
D-Link DIR-618 and DIR-605L - Improper Access Control in /goform/formAdvNetwork
CVSS 4.3
CVE-2025-2546 MEDIUM
D-Link DIR-618 and DIR-605L - Improper Access Control in Firewall Service
CVSS 4.3
CVE-2025-30140 HIGH
G-Net Dashcam BB GONX - Info Disclosure
CVSS 7.5
CVE-2025-30141 HIGH
G-Net Dashcam BB GONX - Info Disclosure
CVSS 7.5
CVE-2025-30138 MEDIUM
G-Net Dashcam BB GONX - Privilege Escalation
CVSS 4.6
CVE-2025-26138 MEDIUM
Systemic Risk Value <= 2.8.0 - Unauthenticated Improper Access Control via Predictable File ID Parameter
CVSS 6.5
CVE-2025-30132 CRITICAL
IROAD Dashcam V - Improper Access Control via Unregistered Public Domain
CVSS 9.1
CVE-2025-25585 HIGH
yimioa < 2024.07.04 - Unauthenticated Administrator Password Modification via WebSecurityConfig
CVSS 7.3
CVE-2025-25500 HIGH
cosmwasm < 2.2.0 - Improper Access Control via Capability Validation Bypass
CVSS 7.5
CVE-2025-25621 MEDIUM
Unifiedtransform 2.0 - Incorrect Access Control via Teacher Attendance Endpoint
CVSS 4.3
CVE-2025-25618 LOW
Unifiedtransform 2.0 - Privilege Escalation via Incorrect Access Control
CVSS 3.3
CVE-2025-2350 MEDIUM
Iroadau Fx2 Firmware < 2025-03-08 - Improper Access Control
CVSS 6.3
CVE-2025-2348 MEDIUM
Iroadau Fx2 Firmware < 2025-03-08 - Information Disclosure
CVSS 4.3
CVE-2025-2334 MEDIUM
springboot-openai-chatgpt e84f6f5 - Improper Access Control in Chat History Handler
CVSS 5.4
CVE-2025-25225 MEDIUM
Hikashop <5.1.3 - Privilege Escalation
CVSS 6.5
CVE-2025-25598 HIGH
Inova Logic CUSTOMER MONITOR 3.1.757.1 - Privilege Escalation via Scheduled Task Executable Injection
CVSS 8.8
CVE-2025-2280 HIGH
Devolutions Server < 2024.3.6.0 - Authenticated Browser Extension Restriction Bypass
CVSS 8.1
CVE-2025-2278 MEDIUM
Devolutions Server < 2025.1.3.0 - Authenticated Improper Access Control in Temporary Access Requests
CVSS 6.5
CVE-2025-25683 MEDIUM
AlekSIS-Core <3.2.1 - Info Disclosure
CVSS 5.6
CVE-2025-20144 MEDIUM
Cisco IOS XR - Unauthenticated Access Control Bypass via Hybrid ACL Processing
CVSS 4.0
CVE-2025-2219 HIGH
LoveCards 2.1.1-2.3.2 - Unauthenticated Unrestricted File Upload via /api/upload/image
CVSS 7.3
Details
Vulnerabilities 5,300