CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
5,300 vulnerabilities with CWE-284
CVE-2025-1881
MEDIUM
i-Drive i11-i12 <20250227 - Improper Access Controls
CVSS 4.3
CVE-2025-25950
HIGH
Academia Student Information System EagleR 1.0.118 - Improper Access Control in /rest/staffResource/update
CVSS 8.1
CVE-2025-25948
CRITICAL
Academia Student Information System EagleR 1.0.118 - Improper Access Control in Staff Resource Creation
CVSS 9.1
CVE-2025-1835
MEDIUM
osuuu LightPicture 1.2.2 - Unrestricted Upload
CVSS 6.3
CVE-2025-1834
MEDIUM
zj1983 zz <2024-8 - Unrestricted Upload
CVSS 6.3
CVE-2025-1818
MEDIUM
zj1983 zz <2024-8 - Unrestricted Upload
CVSS 6.3
CVE-2025-1791
MEDIUM
Zorlan SkyCaiji 2.9 - Unrestricted Upload
CVSS 6.3
CVE-2025-25730
MEDIUM
Motorola Mobility Droid Razr HD - Info Disclosure
CVSS 4.6
CVE-2025-1646
HIGH
Lumsoft ERP 8 - Unrestricted Upload
CVSS 7.3
CVE-2025-27140
CRITICAL
WeGIA < 3.2.15 - OS Command Injection via importar_dump.php Endpoint
CVSS 9.8
CVE-2025-1606
MEDIUM
Best Employee Management System 1.0 - Information Disclosure in Backup File Handler
CVSS 4.3
CVE-2025-1598
MEDIUM
Best Church Management Software 1.0 - Unauthenticated Arbitrary File Upload via photo1 Parameter
CVSS 6.3
CVE-2025-1595
MEDIUM
Anhui Xufan Information Technology EasyCVR <2.7.0 - Info Disclosure
CVSS 5.3
CVE-2025-1593
MEDIUM
Best Employee Management System 1.0 - Unrestricted File Upload in Profile Picture Handler
CVSS 4.7
CVE-2025-1590
MEDIUM
SourceCodester E-Learning System 1.0 - Unrestricted File Upload in List of Lessons Page
CVSS 4.7
CVE-2025-1555
HIGH
hzmanyun Education and Training System 3.1.1 - Unrestricted File Upload via saveImage Function
CVSS 7.3
CVE-2025-25968
MEDIUM
DDSN Interactive cm3 Acora CMS 10.1.1 - Improper Access Control via File Parameter
CVSS 6.0
CVE-2025-21105
MEDIUM
Dell RecoverPoint for Virtual Machines 6.0.X - Authenticated Command Execution via Binary
CVSS 6.6
CVE-2025-24989
HIGH
KEV
Microsoft Power Pages - Unauthenticated Privilege Escalation via Registration Control Bypass
CVSS 8.2
CVE-2025-20153
MEDIUM
Cisco Secure Email Gateway - Auth Bypass
CVSS 5.8
CVE-2025-0968
MEDIUM
ElementsKit Elementor Addons < 3.4.0 - Unauthenticated Sensitive Information Exposure via get_megamenu_content()
CVSS 5.3
CVE-2025-26617
CRITICAL
WeGIA < 3.2.14 - SQL Injection via historico_paciente.php Endpoint
CVSS 9.8
CVE-2025-26616
HIGH
WeGIA < 3.2.14 - Path Traversal via exportar_dump.php Endpoint
CVSS 7.5
CVE-2025-26615
CRITICAL
WeGIA < 3.2.14 - Path Traversal via examples.php Endpoint
CVSS 10.0
CVE-2025-26613
CRITICAL
WeGIA < 3.2.14 - OS Command Injection via gerenciar_backup.php Endpoint
CVSS 9.8
Details
Vulnerabilities
5,300