CWE-284

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

5,300 vulnerabilities with CWE-284
CVE-2025-1881 MEDIUM
i-Drive i11-i12 <20250227 - Improper Access Controls
CVSS 4.3
CVE-2025-25950 HIGH
Academia Student Information System EagleR 1.0.118 - Improper Access Control in /rest/staffResource/update
CVSS 8.1
CVE-2025-25948 CRITICAL
Academia Student Information System EagleR 1.0.118 - Improper Access Control in Staff Resource Creation
CVSS 9.1
CVE-2025-1835 MEDIUM
osuuu LightPicture 1.2.2 - Unrestricted Upload
CVSS 6.3
CVE-2025-1834 MEDIUM
zj1983 zz <2024-8 - Unrestricted Upload
CVSS 6.3
CVE-2025-1818 MEDIUM
zj1983 zz <2024-8 - Unrestricted Upload
CVSS 6.3
CVE-2025-1791 MEDIUM
Zorlan SkyCaiji 2.9 - Unrestricted Upload
CVSS 6.3
CVE-2025-25730 MEDIUM
Motorola Mobility Droid Razr HD - Info Disclosure
CVSS 4.6
CVE-2025-1646 HIGH
Lumsoft ERP 8 - Unrestricted Upload
CVSS 7.3
CVE-2025-27140 CRITICAL
WeGIA < 3.2.15 - OS Command Injection via importar_dump.php Endpoint
CVSS 9.8
CVE-2025-1606 MEDIUM
Best Employee Management System 1.0 - Information Disclosure in Backup File Handler
CVSS 4.3
CVE-2025-1598 MEDIUM
Best Church Management Software 1.0 - Unauthenticated Arbitrary File Upload via photo1 Parameter
CVSS 6.3
CVE-2025-1595 MEDIUM
Anhui Xufan Information Technology EasyCVR <2.7.0 - Info Disclosure
CVSS 5.3
CVE-2025-1593 MEDIUM
Best Employee Management System 1.0 - Unrestricted File Upload in Profile Picture Handler
CVSS 4.7
CVE-2025-1590 MEDIUM
SourceCodester E-Learning System 1.0 - Unrestricted File Upload in List of Lessons Page
CVSS 4.7
CVE-2025-1555 HIGH
hzmanyun Education and Training System 3.1.1 - Unrestricted File Upload via saveImage Function
CVSS 7.3
CVE-2025-25968 MEDIUM
DDSN Interactive cm3 Acora CMS 10.1.1 - Improper Access Control via File Parameter
CVSS 6.0
CVE-2025-21105 MEDIUM
Dell RecoverPoint for Virtual Machines 6.0.X - Authenticated Command Execution via Binary
CVSS 6.6
CVE-2025-24989 HIGH KEV
Microsoft Power Pages - Unauthenticated Privilege Escalation via Registration Control Bypass
CVSS 8.2
CVE-2025-20153 MEDIUM
Cisco Secure Email Gateway - Auth Bypass
CVSS 5.8
CVE-2025-0968 MEDIUM
ElementsKit Elementor Addons < 3.4.0 - Unauthenticated Sensitive Information Exposure via get_megamenu_content()
CVSS 5.3
CVE-2025-26617 CRITICAL
WeGIA < 3.2.14 - SQL Injection via historico_paciente.php Endpoint
CVSS 9.8
CVE-2025-26616 HIGH
WeGIA < 3.2.14 - Path Traversal via exportar_dump.php Endpoint
CVSS 7.5
CVE-2025-26615 CRITICAL
WeGIA < 3.2.14 - Path Traversal via examples.php Endpoint
CVSS 10.0
CVE-2025-26613 CRITICAL
WeGIA < 3.2.14 - OS Command Injection via gerenciar_backup.php Endpoint
CVSS 9.8
Details
Vulnerabilities 5,300