Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
macOS MEDIUM 6.5
CVE-2025-31258

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox.

Fix: 15.5+
Fix from $1,600 2025-05-12
macOS MEDIUM 5.5
CVE-2025-31260

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive use…

Fix: 15.5+
Fix from $1,600 2025-05-12
macOS HIGH 7.5
CVE-2025-31247

A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An …

Fix: 13.7.6 / 14.7.6+
Fix from $1,950 2025-05-12
macOS HIGH 7.1
CVE-2025-31232

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A sandboxed a…

Fix: 13.7.6 / 14.7.6+
Fix from $1,950 2025-05-12
Ipados MEDIUM 5.5
CVE-2025-31212

This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS …

Fix: 2.5 / 11.5+
Fix from $1,600 2025-05-12
macOS MEDIUM 6.3
CVE-2025-31195

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.

Fix: 15.4+
Fix from $1,600 2025-05-12
Ipados CRITICAL 9.1
CVE-2025-30436

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able …

Fix: 18.4+
Fix from $2,300 2025-05-12
Kkfileview CRITICAL 9.8
CVE-2025-4538

A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipula…

Mitigation only
Fix from $2,300 2025-05-11
Group Audio Visual Integrated Management MEDIUM 5.3
CVE-2025-4536

A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classified as critical. Affected by th…

No fix yet
Fix from $1,600 2025-05-11
Group Audio Visual Integrated Management MEDIUM 5.3
CVE-2025-4535

A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0. Affected…

No fix yet
Fix from $1,600 2025-05-11
Rx1800 Firmware MEDIUM 6.8
CVE-2025-28201

An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.

No fix yet
Fix from $1,600 2025-05-09
Online Student Clearance System CRITICAL 9.8
CVE-2025-4468

A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This issue affects some unknown proce…

No fix yet
Fix from $2,300 2025-05-09
Msagsfeedback.azurewebsites.net HIGH 7.5
CVE-2025-33072

Improper access control in Azure allows an unauthorized attacker to disclose information over a network.

Mitigation only
Fix from $1,950 2025-05-08
Ios Xe MEDIUM 6.5
CVE-2025-20190

A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to r…

Mitigation only
Fix from $1,600 2025-05-07
Easy\!appointments HIGH 7.5
CVE-2025-29448

Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a den…

Patch available
Fix from $1,950 2025-05-07
Unclassified CRITICAL 9.4
CVE-2025-46816

goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible fo…

Patch available
Fix from $2,300 2025-05-06
Fastconnect 6700 Firmware HIGH 7.8
CVE-2025-21469

Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.

Mitigation only
Fix from $1,950 2025-05-06
Aqt1000 Firmware HIGH 7.8
CVE-2025-21470

Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.

Mitigation only
Fix from $1,950 2025-05-06
Aqt1000 Firmware HIGH 7.8
CVE-2024-49842

Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.

No fix yet
Fix from $1,950 2025-05-06
Unclassified MEDIUM 6.3
CVE-2025-4333

A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function…

Mitigation only
Fix from $1,600 2025-05-06
Harmonyos HIGH 7.7
CVE-2025-46588

Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confident…

No fix yet
Fix from $1,950 2025-05-06
Harmonyos HIGH 7.1
CVE-2025-46589

Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confident…

No fix yet
Fix from $1,950 2025-05-06
Content Management System MEDIUM 6.3
CVE-2025-4310

A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/…

No fix yet
Fix from $1,600 2025-05-06
Unclassified MEDIUM 6.3
CVE-2025-4305

A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file ap…

Mitigation only
Fix from $1,600 2025-05-06
Ideacms CRITICAL 9.8
CVE-2025-4291

A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unr…

Fix: after 1.6
Fix from $2,300 2025-05-05
Jeeweb Mybatis Springboot MEDIUM 6.5
CVE-2025-45618

Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensi…

No fix yet
Fix from $1,600 2025-05-05
Kob HIGH 7.5
CVE-2025-45609

Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a crafted payloa…

No fix yet
Fix from $1,950 2025-05-05
Passjava HIGH 7.5
CVE-2025-45610

Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a craf…

Fix: after 3.0.0
Fix from $1,950 2025-05-05
Hope Boot CRITICAL 9.8
CVE-2025-45611

Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.

No fix yet
Fix from $2,300 2025-05-05
Xmall CRITICAL 9.8
CVE-2025-45612

Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.

Fix: after 1.1
Fix from $2,300 2025-05-05