Vulnerabilities (CVE)

Filtered by CWE-284
Total 3015 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-2315 1 Ami 1 Aptio V 2025-10-02 N/A 7.1 HIGH
APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected SPI flash modifications and BIOS boot kit launches, also impacting the availability.
CVE-2024-37887 1 Nextcloud 1 Nextcloud Server 2025-10-02 N/A 3.5 LOW
Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1.
CVE-2025-51532 1 Sagedpw 1 Sage Dpw 2025-10-01 N/A 7.5 HIGH
Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted request. The vendor has stated that the issue is fixed in 2025_06_000, released in June 2025.
CVE-2024-55402 1 4cstrategies 1 Exonaut 2025-10-01 N/A 5.3 MEDIUM
4C Strategies Exonaut before v22.4 was discovered to contain an access control issue.
CVE-2025-49692 1 Microsoft 1 Azure Connected Machine Agent 2025-10-01 N/A 7.8 HIGH
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-6532 1 Noyafa 2 Lf9 Pro, Lf9 Pro Firmware 2025-10-01 3.3 LOW 4.3 MEDIUM
A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611. Affected by this vulnerability is an unknown functionality of the component RTSP Live Video Stream Endpoint. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. This dashcam is distributed by multiple resellers and different names.
CVE-2025-7075 1 Blackvuenorthamerica 2 Blackvue Dr590x, Blackvue Dr590x Firmware 2025-10-01 5.8 MEDIUM 6.3 MEDIUM
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /upload.cgi of the component HTTP Endpoint. The manipulation leads to unrestricted upload. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-7076 1 Blackvuenorthamerica 2 Blackvue Dr590x, Blackvue Dr590x Firmware 2025-10-01 4.8 MEDIUM 5.4 MEDIUM
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.cgi of the component Configuration Handler. The manipulation leads to improper access controls. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-52514 1 Nextcloud 1 Nextcloud Server 2025-10-01 N/A 4.1 MEDIUM
Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder inside Nextcloud allowing them to afterwards potentially access the blocked files depending on the user access control rules. It is recommended that the Nextcloud Server is upgraded to 27.1.9, 28.0.5 or 29.0.0 and Nextcloud Enterprise Server is upgraded to 21.0.9.18, 22.2.10.23, 23.0.12.18, 24.0.12.14, 25.0.13.9, 26.0.13.3, 27.1.9, 28.0.5 or 29.0.0.
CVE-2025-53501 2 Mediawiki, Xtex 2 Mediawiki, Scribunto 2025-10-01 N/A 8.8 HIGH
Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - Scribunto Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
CVE-2025-25968 1 Ddsn 1 Cm3 Acora Content Management System 2025-09-30 N/A 6.0 MEDIUM
DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By referencing specific files (e.g., cm3.xml), attackers can bypass access controls, leading to account takeover and potential privilege escalation.
CVE-2025-47794 1 Nextcloud 1 Nextcloud Server 2025-09-30 N/A 2.6 LOW
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system may read temporary files from Nextcloud running with a different user account, or run a symlink attack. Nextcloud Server versions 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1 fix the issue. No known workarounds are available.
CVE-2025-57197 2025-09-30 N/A 6.0 MEDIUM
In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass the current PIN verification check and directly modify the authentication PIN. This allows unauthorized users to change PIN without knowing the original/current PIN.
CVE-2024-10241 1 Mattermost 1 Mattermost Server 2025-09-30 N/A 4.3 MEDIUM
Mattermost versions 9.5.x <= 9.5.9 fail to properly filter the channel data when ElasticSearch is enabled which allows a user to get private channel names by using cmd+K/ctrl+K.
CVE-2024-5272 1 Mattermost 1 Mattermost Server 2025-09-30 N/A 4.3 MEDIUM
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.
CVE-2024-5270 1 Mattermost 1 Mattermost Server 2025-09-30 N/A 4.3 MEDIUM
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch their authentication mail from SAML to email and possibly edit personal details that were otherwise non-editable and provided by the SAML provider.
CVE-2025-43294 1 Apple 1 Macos 2025-09-30 N/A 3.3 LOW
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.
CVE-2025-43308 1 Apple 1 Macos 2025-09-30 N/A 5.3 MEDIUM
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access sensitive user data.
CVE-2025-43328 1 Apple 1 Macos 2025-09-30 N/A 3.3 LOW
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user data.
CVE-2025-43332 1 Apple 1 Macos 2025-09-30 N/A 5.2 MEDIUM
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to break out of its sandbox.