Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Devolutions Server HIGH 8.1
CVE-2025-2280

Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass th…

Fix: 2024.3.6.0+
Fix from $1,950 2025-03-13
Unclassified MEDIUM 5.6
CVE-2025-25683

AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects AlekSIS-Core 3.0, 3.1, 3.1.1, 3.…

Mitigation only
Fix from $1,600 2025-03-12
Ios Xr MEDIUM 5.8
CVE-2025-20144

A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote at…

Mitigation only
Fix from $1,600 2025-03-12
Lovecards CRITICAL 9.8
CVE-2025-2218

A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /…

Fix: after 2.3.2
Fix from $2,300 2025-03-12
Lovecards CRITICAL 9.8
CVE-2025-2219

A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /ap…

Fix: after 2.3.2
Fix from $2,300 2025-03-12
Warehouse Refinement Management System CRITICAL 9.8
CVE-2025-2216

A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the…

No fix yet
Fix from $2,300 2025-03-12
Riva CRITICAL 9.8
CVE-2025-23242

NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead…

Fix: 2.19.0+
Fix from $2,300 2025-03-11
Riva CRITICAL 9.1
CVE-2025-23243

NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead…

Fix: 2.19.0+
Fix from $2,300 2025-03-11
Windows 10 1507 HIGH 8.8
CVE-2025-26645

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.10240.20947 / 10.0.14393.7876+
Fix from $1,950 2025-03-11
Windows 11 22h2 HIGH 7.3
CVE-2025-24994

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22621.5039 / 10.0.22631.5039+
Fix from $1,950 2025-03-11
Windows 11 22h2 HIGH 7.3
CVE-2025-24076

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.22621.5039 / 10.0.22631.5039+
Fix from $1,950 2025-03-11
Unclassified HIGH 7.8
CVE-2024-9157

** UNSUPPORTED WHEN ASSIGNED **  A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local…

Mitigation only
Fix from $1,950 2025-03-11
Unifiedtransform HIGH 8.8
CVE-2025-25614

Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.

No fix yet
Fix from $1,950 2025-03-10
F800 Pro Firmware HIGH 8.8
CVE-2025-2121

A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the compon…

No fix yet
Fix from $1,950 2025-03-09
Warehouse Refinement Management System CRITICAL 9.8
CVE-2025-2115

A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRe…

No fix yet
Fix from $2,300 2025-03-09
Starsea Mall MEDIUM 5.4
CVE-2025-2089

A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUse…

No fix yet
Fix from $1,600 2025-03-07
Unclassified HIGH 7.5
CVE-2025-25381

Incorrect access control in the KSRTC AWATAR app of Karnataka State Road Transport Corporation v1.3.0 allows to view sensitive information such as us…

Mitigation only
Fix from $1,950 2025-03-06
Ecommerce Website Using Php CRITICAL 9.8
CVE-2025-2035

A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality…

No fix yet
Fix from $2,300 2025-03-06
Chestnutcms HIGH 7.6
CVE-2025-2031

A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile of the file /dev-api/cms/file/…

No fix yet
Fix from $1,950 2025-03-06
Traffic Server MEDIUM 6.3
CVE-2024-56195

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 thro…

Fix: 9.2.9 / 10.0.4+
Fix from $1,600 2025-03-06
Traffic Server MEDIUM 6.3
CVE-2024-56196

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are rec…

Fix: 10.0.4+
Fix from $1,600 2025-03-06
Vasion Print CRITICAL 9.8
CVE-2025-27646

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Edit User Account Exposure V-2024-001.

Fix: 20.0.2253 / 22.0.913+
Fix from $2,300 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27649

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.893 Application 20.0.2140 allows Incorrect Access Control: PHP V-2023-016.

Fix: 20.0.2140 / 22.0.893+
Fix from $2,300 2025-03-05
Unclassified HIGH 7.7
CVE-2025-1259

On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can resu…

No fix yet
Fix from $1,950 2025-03-04
Unclassified CRITICAL 9.1
CVE-2025-1260

On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can resu…

No fix yet
Fix from $2,300 2025-03-04
Asyncos MEDIUM 5.3
CVE-2020-3122

A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthent…

Mitigation only
Fix from $1,600 2025-03-04
Firefox CRITICAL 9.1
CVE-2025-1941

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE…

Fix: 136.0+
Fix from $2,300 2025-03-04
Shishuocms CRITICAL 9.8
CVE-2025-1890

A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/ma…

No fix yet
Fix from $2,300 2025-03-04
I11 Firmware HIGH 7.0
CVE-2025-1882

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality …

Fix: after 20250227
Fix from $1,950 2025-03-03
Arcgis Server HIGH 8.5
CVE-2024-51954

There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allo…

Fix: after 11.3
Fix from $1,950 2025-03-03