Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified HIGH 7.3
CVE-2025-2705

A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadAp…

Mitigation only
Fix from $1,950 2025-03-24
Unclassified MEDIUM 6.3
CVE-2025-2702

A vulnerability, which was classified as critical, has been found in Softwin WMX3 3.1. This issue affects the function ImageAdd of the file /ImageAdd…

Mitigation only
Fix from $1,600 2025-03-24
Unclassified MEDIUM 6.5
CVE-2025-2686

A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified a…

Mitigation only
Fix from $1,600 2025-03-24
Elearning System CRITICAL 9.8
CVE-2025-2687

A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php…

No fix yet
Fix from $2,300 2025-03-24
Unclassified MEDIUM 6.3
CVE-2025-2671

A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affects the function base64im…

Mitigation only
Fix from $1,600 2025-03-23
Best Church Management Software MEDIUM 6.3
CVE-2025-2606

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is …

No fix yet
Fix from $1,600 2025-03-21
Lzcms Laozhangbokexitong MEDIUM 6.3
CVE-2025-2607

A vulnerability was found in phplaozhang LzCMS-LaoZhangBoKeXiTong up to 1.1.4. It has been rated as critical. Affected by this issue is some unknown …

Fix: after 1.1.4
Fix from $1,600 2025-03-21
Loxilb HIGH 7.4
CVE-2024-53348

LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privileges.

Fix: after 0.9.7
Fix from $1,950 2025-03-21
Unclassified MEDIUM 5.5
CVE-2025-2557

A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is some unknown functionality of th…

Mitigation only
Fix from $1,600 2025-03-20
Dir 618 Firmware HIGH 8.8
CVE-2025-2549

A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this vulnerability is an unknown f…

No fix yet
Fix from $1,950 2025-03-20
Dir 618 Firmware HIGH 8.8
CVE-2025-2548

A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an unknown function of the file…

No fix yet
Fix from $1,950 2025-03-20
Stable Diffusion Webui CRITICAL 9.6
CVE-2024-11045

A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious…

No fix yet
Fix from $2,300 2025-03-20
G Onx Firmware HIGH 7.5
CVE-2025-30140

An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered public d…

Mitigation only
Fix from $1,950 2025-03-18
G Onx Firmware HIGH 7.5
CVE-2025-30141

An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream. It exposes API endpoints on …

Mitigation only
Fix from $1,950 2025-03-18
Risk Value MEDIUM 6.5
CVE-2025-26138

Systemic Risk Value <=2.8.0 is vulnerable to improper access control in /RiskValue/GroupingEntities/Controls/GetFile.aspx?ID=. Uploaded files are acc…

Fix: after 2.8.0
Fix from $1,600 2025-03-18
Unclassified CRITICAL 9.1
CVE-2025-30132

An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, creating a security risk. Durin…

Mitigation only
Fix from $2,300 2025-03-18
Yimioa HIGH 7.3
CVE-2025-25585

Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily mo…

Fix: 2024.07.04+
Fix from $1,950 2025-03-18
Tastyigniter HIGH 8.1
CVE-2024-44313

TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to …

No fix yet
Fix from $1,950 2025-03-18
Cosmwasm HIGH 7.5
CVE-2025-25500

An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability val…

Fix: 2.2.0+
Fix from $1,950 2025-03-18
Fortimail CRITICAL 9.8
CVE-2023-47539

An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a rem…

Mitigation only
Fix from $2,300 2025-03-18
macOS MEDIUM 5.5
CVE-2024-54559

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.

Fix: 15.2+
Fix from $1,600 2025-03-17
macOS MEDIUM 6.2
CVE-2024-54565

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.

Fix: 15.2+
Fix from $1,600 2025-03-17
Fortiwlc MEDIUM 6.7
CVE-2021-22126

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2…

Fix: 8.5.3+
Fix from $1,600 2025-03-17
Fortiwlc MEDIUM 5.3
CVE-2021-32584

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and bel…

Fix: 8.5.4+
Fix from $1,600 2025-03-17
Fx2 Firmware HIGH 7.8
CVE-2025-2350

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been rated as critical. Affected by this issue is some unknown functionality o…

Fix: after 2025-03-08
Fix from $1,950 2025-03-16
Fx2 Firmware MEDIUM 5.5
CVE-2025-2348

A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an unknown function of the file /m…

Fix: after 2025-03-08
Fix from $1,600 2025-03-16
Springboot Openai Chatgpt CRITICAL 9.1
CVE-2025-2334

A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the …

No fix yet
Fix from $2,300 2025-03-15
Hikashop MEDIUM 6.5
CVE-2025-25225

A privilege escalation vulnerability in the Hikashop component versions 1.0.0-5.1.3 for Joomla allows authenticated attackers (administrator) to esca…

Fix: after 5.1.3
Fix from $1,600 2025-03-15
Customer Monitor HIGH 8.8
CVE-2025-25598

Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via p…

Mitigation only
Fix from $1,950 2025-03-13
Devolutions Server MEDIUM 6.5
CVE-2025-2278

Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authentica…

Fix: 2025.1.3.0+
Fix from $1,600 2025-03-13