Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Studentmanager HIGH 7.2
CVE-2025-3565

A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affects unknown code of the file /u…

No fix yet
Fix from $1,950 2025-04-14
Uzy Ssm Mall CRITICAL 9.8
CVE-2025-3558

A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uplo…

No fix yet
Fix from $2,300 2025-04-14
Visual Studio Code MEDIUM 6.8
CVE-2025-32726

Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.

Fix: 1.99.1+
Fix from $1,600 2025-04-12
Unclassified HIGH 8.4
CVE-2025-23389

A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first logi…

Mitigation only
Fix from $1,950 2025-04-11
Commerce MEDIUM 5.3
CVE-2025-27190

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability th…

Mitigation only
Fix from $1,600 2025-04-08
Commerce MEDIUM 5.3
CVE-2025-27191

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability th…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2025-04-08
Coldfusion HIGH 8.2
CVE-2025-30288

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security fea…

Mitigation only
Fix from $1,950 2025-04-08
Coldfusion CRITICAL 9.1
CVE-2025-30281EPSS 20%

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code…

Mitigation only
Fix from $2,300 2025-04-08
Visual Studio 2022 HIGH 7.3
CVE-2025-29804

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Fix: 17.8.20 / 17.10.13+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.5
CVE-2025-29810

Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Office HIGH 7.8
CVE-2025-27744

Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.

Mitigation only
Fix from $1,950 2025-04-08
Windows 10 1507 MEDIUM 6.5
CVE-2025-27738

Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,600 2025-04-08
Windows 10 1809 HIGH 8.4
CVE-2025-26678

Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.

Fix: 10.0.17763.7136 / 10.0.19044.5737+
Fix from $1,950 2025-04-08
Windows 10 1507 MEDIUM 6.5
CVE-2025-21197

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't hav…

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,600 2025-04-08
Aias HIGH 8.8
CVE-2025-3410

A vulnerability classified as critical was found in mymagicpower AIAS 20250308. This vulnerability affects unknown code of the file training_platform…

No fix yet
Fix from $1,950 2025-04-08
Vblog CRITICAL 9.8
CVE-2025-3398

A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function configure of the file blo…

Mitigation only
Fix from $2,300 2025-04-08
Ruoyi HIGH 8.8
CVE-2025-28409

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly valida…

No fix yet
Fix from $1,950 2025-04-07
Ruoyi CRITICAL 9.8
CVE-2025-28410

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the req…

No fix yet
Fix from $2,300 2025-04-07
Ruoyi CRITICAL 9.8
CVE-2025-28411

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

No fix yet
Fix from $2,300 2025-04-07
Ruoyi CRITICAL 9.8
CVE-2025-28412

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

No fix yet
Fix from $2,300 2025-04-07
Ruoyi CRITICAL 9.8
CVE-2025-28413

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

No fix yet
Fix from $2,300 2025-04-07
Ruoyi CRITICAL 9.8
CVE-2025-28402

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

No fix yet
Fix from $2,300 2025-04-07
Ruoyi HIGH 7.2
CVE-2025-28403

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting u…

No fix yet
Fix from $1,950 2025-04-07
Ruoyi CRITICAL 9.8
CVE-2025-28405

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

No fix yet
Fix from $2,300 2025-04-07
Ruoyi CRITICAL 9.8
CVE-2025-28406

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

No fix yet
Fix from $2,300 2025-04-07
Ruoyi HIGH 8.8
CVE-2025-28407

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly valida…

No fix yet
Fix from $1,950 2025-04-07
Ruoyi CRITICAL 9.8
CVE-2025-28408

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does…

No fix yet
Fix from $2,300 2025-04-07
Qam8255p Firmware HIGH 7.8
CVE-2025-21425

Memory corruption may occur due top improper access control in HAB process.

No fix yet
Fix from $1,950 2025-04-07
Nimrod HIGH 8.8
CVE-2025-3324

A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown funct…

No fix yet
Fix from $1,950 2025-04-06
Admintwo HIGH 7.5
CVE-2025-3256

A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file…

No fix yet
Fix from $1,950 2025-04-04