Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Shiro Action HIGH 7.5
CVE-2025-45613

Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.

Fix: after 0.6
Fix from $1,950 2025-05-05
One HIGH 7.5
CVE-2025-45614

Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload.

No fix yet
Fix from $1,950 2025-05-05
Yaoqishan CRITICAL 9.8
CVE-2025-45615

Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request.

No fix yet
Fix from $2,300 2025-05-05
Brcc CRITICAL 9.8
CVE-2025-45616

Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.

Fix: after 1.2.0
Fix from $2,300 2025-05-05
Production Ssm HIGH 7.5
CVE-2025-45617

Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted…

No fix yet
Fix from $1,950 2025-05-05
Xinguan HIGH 7.5
CVE-2025-45608

Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a craft…

Fix: after 0.0.1-snapshot
Fix from $1,950 2025-05-05
Chrome MEDIUM 6.3
CVE-2025-4051

Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific…

Fix: 136.0.7103.59+
Fix from $1,600 2025-05-05
Dbsyncer HIGH 7.5
CVE-2025-45237

Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account i…

No fix yet
Fix from $1,950 2025-05-05
A720r Firmware HIGH 7.5
CVE-2025-4270EPSS 13%

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/…

No fix yet
Fix from $1,950 2025-05-05
A720r Firmware MEDIUM 5.3
CVE-2025-4271

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functional…

No fix yet
Fix from $1,600 2025-05-05
A720r Firmware MEDIUM 5.3
CVE-2025-4269

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/c…

No fix yet
Fix from $1,600 2025-05-05
Newbee Mall CRITICAL 9.8
CVE-2025-4259

A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/n…

No fix yet
Fix from $2,300 2025-05-05
Youkefu HIGH 8.8
CVE-2025-4258

A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youk…

Fix: after 4.2.0
Fix from $1,950 2025-05-05
Replyone CRITICAL 9.1
CVE-2024-48905

Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.

No fix yet
Fix from $2,300 2025-05-01
Rx2 Pro Firmware HIGH 7.1
CVE-2025-46635

An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces…

No fix yet
Fix from $1,950 2025-05-01
Rx2 Pro Firmware HIGH 7.3
CVE-2025-46628

Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain…

No fix yet
Fix from $1,950 2025-05-01
Rx2 Pro Firmware MEDIUM 6.5
CVE-2025-46629

Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthor…

No fix yet
Fix from $1,600 2025-05-01
Dataease CRITICAL 9.8
CVE-2025-46566

DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC lin…

Fix: 2.10.9+
Fix from $2,300 2025-05-01
Opencti MEDIUM 6.3
CVE-2025-24887

OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed,…

Fix: after 6.4.10
Fix from $1,600 2025-04-30
Helm Charts CRITICAL 9.8
CVE-2025-46331

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v…

Fix: 0.2.29 / 1.8.11+
Fix from $2,300 2025-04-30
Couchbase Server HIGH 7.6
CVE-2025-46619

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized acce…

Fix: 7.2.7 / 7.6.4+
Fix from $1,950 2025-04-30
Joplin HIGH 8.8
CVE-2025-27134

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version …

Fix: 3.3.3+
Fix from $1,950 2025-04-30
Mall HIGH 7.5
CVE-2025-4119

A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the compon…

Mitigation only
Fix from $1,950 2025-04-30
Mall CRITICAL 9.1
CVE-2025-4118

A vulnerability classified as critical has been found in Weitong Mall 1.0.0. This affects an unknown part of the file /historyList of the component P…

Mitigation only
Fix from $2,300 2025-04-30
Unclassified MEDIUM 6.3
CVE-2025-46552

KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some comm…

Patch available
Fix from $1,600 2025-04-29
Unclassified CRITICAL 9.8
CVE-2025-25962

An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function

Mitigation only
Fix from $2,300 2025-04-29
Online Traveling System HIGH 7.5
CVE-2025-4065

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerability affects unknown code of …

Mitigation only
Fix from $1,950 2025-04-29
Online Traveling System CRITICAL 9.8
CVE-2025-4066

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of …

Mitigation only
Fix from $2,300 2025-04-29
Online Traveling System MEDIUM 5.3
CVE-2025-4067

A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admi…

Mitigation only
Fix from $1,600 2025-04-29
Online Traveling System MEDIUM 5.3
CVE-2025-4064

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file …

Mitigation only
Fix from $1,600 2025-04-29