← Back
CWE-284

5,090 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenve
1Vblog
Oct 15, 2025
Apr 8, 2025
5.3 MEDIUM· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blogserver/src/main/java/org/sang/config/WebSecurityConfig.java. The manip...Show more
A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blogserver/src/main/java/org/sang/config/WebSecurityConfig.java. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under...Show more
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentIdShow less
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified d...Show more
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictIdShow less
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to syst...Show more
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settingsShow less
1Ruoyi
1Ruoyi
Apr 9, 2025
Apr 7, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
1Qualcomm
33Qam8255p Firmware
Qam8295p FirmwareQam8620p Firmware+30 more
Aug 19, 2025
Apr 7, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption may occur due top improper access control in HAB process.
1Iteaj
1Iboot
Apr 8, 2025
Apr 6, 2025
5.3 MEDIUM· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part of the file /core/admin/pwd of the component Admin Password Handler. The manipulation of the argume...Show more
A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part of the file /core/admin/pwd of the component Admin Password Handler. The manipulation of the argument ID leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Godcheese
1Nimrod
Apr 7, 2025
Apr 6, 2025
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown functionality of the file FileRestController.java. The manipulation of the a...Show more
A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown functionality of the file FileRestController.java. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
11902756969
1Ikun Library
Apr 8, 2025
Apr 5, 2025
5.3 MEDIUM· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerability affects the function addInterceptors of the file MvcConfig.java of the component Borrow Handle...Show more
A vulnerability has been found in 1902756969/code-projects IKUN_Library 1.0 and classified as problematic. This vulnerability affects the function addInterceptors of the file MvcConfig.java of the component Borrow Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Oretnom23
1Online Eyewear Shop
Apr 8, 2025
Apr 5, 2025
5.3 MEDIUM· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of th...Show more
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registration Handler. The manipulation of the argument email leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Xujiangfei
1Admintwo
Oct 9, 2025
Apr 4, 2025
5.3 MEDIUM· v4
7.5 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipulation of the argument email leads to impro...Show more
A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipulation of the argument email leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Xujiangfei
1Admintwo
Oct 9, 2025
Apr 4, 2025
5.3 MEDIUM· v4
7.5 HIGH· v3
4.0 MEDIUM· v2
A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/home. The manipulation of the argument ID leads to i...Show more
A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/home. The manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Senior Walter
1Web Based Pharmacy Product Management System
May 14, 2025
Apr 4, 2025
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add-admin.php of the...Show more
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add-admin.php of the component Create User Page. The manipulation of the argument Avatar leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less