Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Novel CRITICAL 9.8
CVE-2025-4036

A vulnerability was found in 201206030 Novel 3.5.0 and classified as critical. This issue affects the function updateBookChapter of the file src/main…

No fix yet
Fix from $2,300 2025-04-28
Unclassified HIGH 7.5
CVE-2025-32470

A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.

No fix yet
Fix from $1,950 2025-04-28
Lecms HIGH 7.5
CVE-2025-3978

A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file…

No fix yet
Fix from $1,950 2025-04-27
Ecommerce Website In Php MEDIUM 5.3
CVE-2025-3975

A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of…

No fix yet
Fix from $1,600 2025-04-27
News Publishing Site Dashboard CRITICAL 9.8
CVE-2025-3969

A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processi…

No fix yet
Fix from $2,300 2025-04-27
Paicoding MEDIUM 5.3
CVE-2025-3966

A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unknown functionality of the file…

No fix yet
Fix from $1,600 2025-04-27
Dify HIGH 7.6
CVE-2025-43862

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even thou…

Fix: 0.6.12+
Fix from $1,950 2025-04-25
Klims HIGH 7.3
CVE-2025-43947

Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, su…

Fix: after 1.6_dev
Fix from $1,950 2025-04-22
Flaskblog CRITICAL 9.1
CVE-2025-28104

Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.

No fix yet
Fix from $2,300 2025-04-21
Mojoportal MEDIUM 6.5
CVE-2025-28367

mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this v…

Fix: 2.9.1.0+
Fix from $1,600 2025-04-21
Kuangsimplebbs CRITICAL 9.8
CVE-2025-3830

A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUplo…

No fix yet
Fix from $2,300 2025-04-20
My Bbs CRITICAL 9.8
CVE-2025-3807

A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com…

No fix yet
Fix from $2,300 2025-04-19
Wcms HIGH 7.2
CVE-2025-3798

A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminContr…

No fix yet
Fix from $1,950 2025-04-19
Unclassified CRITICAL 9.1
CVE-2025-28233

Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1…

Mitigation only
Fix from $2,300 2025-04-18
Unclassified CRITICAL 9.1
CVE-2025-28231

Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privil…

Mitigation only
Fix from $2,300 2025-04-18
Dify MEDIUM 6.5
CVE-2025-32795

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are impro…

Fix: 0.6.12+
Fix from $1,600 2025-04-18
Dify MEDIUM 6.5
CVE-2025-32796

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enabl…

Fix: after 0.6.8
Fix from $1,600 2025-04-18
Optimod 5950 Firmware CRITICAL 9.8
CVE-2025-28229

Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator …

No fix yet
Fix from $2,300 2025-04-18
Jmb0150 Firmware CRITICAL 9.1
CVE-2025-28232

Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authenticat…

No fix yet
Fix from $2,300 2025-04-18
Jsite MEDIUM 5.3
CVE-2025-3790

A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /druid/index.html of the compone…

No fix yet
Fix from $1,600 2025-04-18
Web Based Pharmacy Product Management System CRITICAL 9.8
CVE-2025-3783

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability i…

No fix yet
Fix from $2,300 2025-04-18
Web Based Pharmacy Product Management System HIGH 8.8
CVE-2025-3764

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unkno…

No fix yet
Fix from $1,950 2025-04-17
Web Based Pharmacy Product Management System HIGH 8.8
CVE-2025-3765

A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affe…

No fix yet
Fix from $1,950 2025-04-17
Unclassified CRITICAL 9.0
CVE-2025-3113

A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database configurations can leverage the …

Mitigation only
Fix from $2,300 2025-04-17
Chrome Os HIGH 8.8
CVE-2025-1568

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit acc…

Mitigation only
Fix from $1,950 2025-04-16
Unclassified MEDIUM 6.5
CVE-2024-53304

An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands vi…

Mitigation only
Fix from $1,600 2025-04-16
A3700r Firmware MEDIUM 5.3
CVE-2025-3675

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServ…

No fix yet
Fix from $1,600 2025-04-16
A3700r Firmware MEDIUM 5.3
CVE-2025-3674

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function …

No fix yet
Fix from $1,600 2025-04-16
A3700r Firmware MEDIUM 5.3
CVE-2025-3668

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setSche…

No fix yet
Fix from $1,600 2025-04-16
A3700r Firmware MEDIUM 5.3
CVE-2025-3667

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the f…

No fix yet
Fix from $1,600 2025-04-16