VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1097 CVEsRSS

CVE-2025-43418Medium· 4.6
10mo ago

This issue was addressed by restricting options offered on a locked device

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive …

▾ Sunlitapple · ipadosEPSS 0.18%via NVD
CVE-2025-43499Medium· 5.5
10mo ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.18%via NVD
CVE-2025-43454High· 7.5
10mo ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. A device may persistently fail to lock.

▾ Twilightapple · ipadosEPSS 0.43%via NVD
CVE-2025-43450High· 7.5
10mo ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to learn information about the current camera view before being granted camera access.

▾ Twilightapple · ipadosEPSS 0.38%via NVD
CVE-2025-43309Low· 2.4
10mo ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2025-56219High· 7.1PoC
11mo ago

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user acco…

▾ Midnightascertia · signinghubEPSS 0.32%via NVD
CVE-2025-9804Critical· 9.6
11mo ago

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform una…

▾ Midnightwso2 · api_control_planeEPSS 0.56%via NVD
CVE-2025-54603Critical· 9.0
11mo ago

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

▾ MidnightEPSS 0.75%via NVD
CVE-2025-20316Medium· 5.3
1y ago

A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL on an affected device. …

A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL on an affected device. …

▾ SunlitEPSS 0.34%via NVD
CVE-2025-20339Medium· 5.8
1y ago

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the improper enforceme…

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the improper enforceme…

▾ SunlitEPSS 0.32%via NVD
CVE-2025-5962High· 7.7
1y ago

A flaw was found in the Lightspeed history service

A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to access and manipulate the chat history of another user on the same system. By abusing inter-process communication calls…

▾ TwilightEPSS 0.23%via NVD
CVE-2025-10616Medium· 6.3
1y ago

A security flaw has been discovered in itsourcecode E-Commerce Website 1.0

A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit h…

▾ Sunlitangeljudesuarez · e-commerce_websiteEPSS 0.46%via NVD
CVE-2025-10615Medium· 6.3
1y ago

A vulnerability was identified in itsourcecode E-Commerce Website 1.0

A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit is …

▾ Sunlitangeljudesuarez · e-commerce_websiteEPSS 0.36%via NVD
CVE-2025-10608Medium· 6.3
1y ago

A vulnerability was detected in Portabilis i-Educar up to 2.10

A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Performing manipulation results in improper access controls. The attack is possible to be carri…

▾ Sunlitportabilis · i-educarEPSS 0.38%via NVD
CVE-2025-10600High· 7.3
1y ago

A flaw has been found in SourceCodester Online Exam Form Submission 1.0

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulation of the argument img causes unrestricted upload. It is possible to initiate the attack …

▾ Twilightjanobe · online_exam_form_submissionEPSS 0.46%via NVD
CVE-2025-10201High· 8.8
1y ago

Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page

Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.26%via NVD
CVE-2025-20159Medium· 5.3
1y ago

A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass configured ACLs for the SSH, NetConf, and gRPC features. This …

A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass configured ACLs for the SSH, NetConf, and gRPC features. This …

▾ SunlitEPSS 0.32%via NVD
CVE-2025-10072Medium· 6.3PoC
1y ago

A vulnerability was found in Portabilis i-Educar up to 2.10

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls. It is possible to initi…

▾ Twilightportabilis · i-educarEPSS 0.32%via NVD
CVE-2024-44271Low· 3.3
1y ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record the screen without an indicator.

▾ Sunlitapple · macosEPSS 0.13%via NVD
CVE-2025-20131Medium· 4.9
1y ago

A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of…

A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of…

▾ Sunlitcisco · identity_services_engineEPSS 0.30%via NVD
CVE-2025-51529Medium· 5.3PoC
1y ago

Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…

Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…

▾ Twilightfollowmedarling · cookies_and_content_security_policyEPSS 0.44%via NVD
CVE-2025-45729Medium· 6.3
1y ago

D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.

D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.

▾ Sunlitdlink · dir-823_pro_firmwareEPSS 0.37%via NVD
CVE-2025-44619Critical· 9.1
1y ago

Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.

Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.

▾ Midnighttinxy · wifi_lock_controller_v1_rf_firmwareEPSS 0.46%via NVD
CVE-2025-30714Medium· 4.8
1y ago

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python)

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via…

▾ Sunlitoracle · mysql_connector/pythonEPSS 0.40%via NVD
CVE-2025-1391Medium· 5.4
1y ago

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email matches the organization’s domain pattern. This issue occurs at the mapper level, leadin…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.41%via NVD
CVE-2025-23367Medium· 6.5
1y ago

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can sus…

▾ Sunlitredhat · jboss_enterprise_application_platformEPSS 0.77%via NVD
CVE-2024-43590High· 7.8
1y ago

Visual C++ Redistributable Installer Elevation of Privilege Vulnerability

Visual C++ Redistributable Installer Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · visual_c++_redistributableEPSS 0.43%via NVD
CVE-2024-45509Medium· 6.5
2y ago

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

▾ Sunlitmisp-project · mispEPSS 0.40%via NVD
CVE-2024-40766Critical· 9.8CISA KEVPoC
2y ago

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects So…

▾ Hadalsonicwall · sonicosEPSS 18%via NVD
CVE-2024-29060Medium· 6.7
2y ago

Visual Studio Elevation of Privilege Vulnerability

Visual Studio Elevation of Privilege Vulnerability

▾ Sunlitmicrosoft · visual_studio_2017EPSS 0.89%via NVD
CWE-284 vulnerabilities (CVEs) — page 36 · VulnSea