CWE-284
5,077 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,077)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote m...Show more |
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote m...Show more |
1Microsoft 17Powershell Windows 10 1507Windows 10 1607+14 moreOct 20, 2025 Oct 14, 2025 N/A· v4 7.3 HIGH· v3 N/A· v2 Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. |
Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity. |
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thunderbird 144. |
1Ericsson 1Network Manager Oct 21, 2025 Oct 13, 2025 6.9 MEDIUM· v4 9.8 CRITICAL· v3 N/A· v2 Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege. |
1Oranbyte 1School Management System Apr 29, 2026 Oct 13, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this issue is some unknown functionality of the file /assets/uploadSllyabus.php....Show more |
1Oranbyte 1School Management System Apr 29, 2026 Oct 13, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this vulnerability is an unknown functionality of the file /assets/uploadNotes.php. This m...Show more |
1Oranbyte 1School Management System Apr 29, 2026 Oct 13, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected is an unknown function of the file /assets/changeSllyabus.php. The manipulation of the...Show more |
1Oranbyte 1School Management System Apr 29, 2026 Oct 13, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This impacts an unknown function of the file /assets/createNotice.php. The manipu...Show more |
1Oranbyte 1School Management System Apr 29, 2026 Oct 13, 2025 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown function of the file /assets/editNotes.php. Executing manipulation of...Show more |
A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unres...Show more |
1Furbo 2Furbo 360 Dog Camera Firmware Furbo Mini FirmwareApr 29, 2026 Oct 12, 2025 1.3 LOW· v4 6.8 MEDIUM· v3 1.8 LOW· v2 A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component GATT Service. This manipulation of the argument DeviceToken causes information disclosure. The attack...Show more |
1Furbo 2Furbo 360 Dog Camera Firmware Furbo Mini FirmwareApr 29, 2026 Oct 12, 2025 2.1 LOW· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the component GATT Service. The manipulation results in improper access controls. The attack can only be perfor...Show more |
1Furbo 2Furbo 360 Dog Camera Firmware Furbo Mini FirmwareOct 30, 2025 Oct 12, 2025 1.0 LOW· v4 6.4 MEDIUM· v3 3.7 LOW· v2 A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This manipulation causes improper access controls. It is feasible to perfor...Show more |
1Furbo 2Furbo 360 Dog Camera Firmware Furbo Mini FirmwareOct 30, 2025 Oct 12, 2025 2.4 LOW· v4 4.6 MEDIUM· v3 2.1 LOW· v2 A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. This affects an unknown part of the component UART Interface. The manipulation results in information disclosure. An attack on the physical device...Show more |
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider implementation for External Se...Show more |
1Code Projects 1Simple Car Rental System Oct 16, 2025 Oct 10, 2025 N/A· v4 9.9 CRITICAL· v3 N/A· v2 code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations. |
1Senior Walter 1Online Student Clearance System Oct 21, 2025 Oct 10, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitiv...Show more |
Azure Entra ID Elevation of Privilege Vulnerability |