Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Student Information System CRITICAL 9.1
CVE-2025-25948EPSS 7%

Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v…

No fix yet
Fix from $2,300 2025-03-03
Academia Student Information System HIGH 8.1
CVE-2025-25950

Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v…

Mitigation only
Fix from $1,950 2025-03-03
Unclassified MEDIUM 6.3
CVE-2025-1835

A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the function upload of the file /ap…

Mitigation only
Fix from $1,600 2025-03-02
Zz CRITICAL 9.8
CVE-2025-1834

A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of the file /resolve. The manipu…

Fix: after 2024-8
Fix from $2,300 2025-03-02
Zz CRITICAL 9.8
CVE-2025-1818

A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unknown processing of the file s…

Fix: after 2024-8
Fix from $2,300 2025-03-02
Skycaiji CRITICAL 9.8
CVE-2025-1791

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vend…

Mitigation only
Fix from $2,300 2025-03-01
Nios CRITICAL 9.8
CVE-2024-37566

Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.

Fix: after 8.6.4
Fix from $2,300 2025-02-27
Nios CRITICAL 9.1
CVE-2024-37567

Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.

Fix: after 8.6.4
Fix from $2,300 2025-02-27
Xiq Se HIGH 8.8
CVE-2024-38291

In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.

Fix: 24.2.11+
Fix from $1,950 2025-02-27
Unifiedtransform CRITICAL 9.8
CVE-2024-53573

Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for admi…

No fix yet
Fix from $2,300 2025-02-26
Odoo MEDIUM 6.5
CVE-2024-36259

Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive inf…

No fix yet
Fix from $1,600 2025-02-25
Odoo HIGH 8.8
CVE-2024-12368

Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens o…

No fix yet
Fix from $1,950 2025-02-25
Enfold MEDIUM 5.3
CVE-2024-13693

The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all version…

Fix: 7.0+
Fix from $1,600 2025-02-25
Unclassified HIGH 7.3
CVE-2025-1646

A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unknown functionality of the file …

Mitigation only
Fix from $1,950 2025-02-25
Unclassified MEDIUM 6.5
CVE-2024-53542

Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows at…

Mitigation only
Fix from $1,600 2025-02-24
Wegia CRITICAL 9.8
CVE-2025-27140

WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA app…

Fix: 3.2.15+
Fix from $2,300 2025-02-24
Best Church Management Software CRITICAL 9.8
CVE-2025-1598

A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is …

No fix yet
Fix from $2,300 2025-02-24
Best Employee Management System HIGH 7.5
CVE-2025-1606

A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of…

No fix yet
Fix from $1,950 2025-02-24
Unclassified MEDIUM 5.3
CVE-2025-1595

A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects un…

No fix yet
Fix from $1,600 2025-02-23
Best Employee Management System CRITICAL 9.8
CVE-2025-1593

A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file…

Mitigation only
Fix from $2,300 2025-02-23
E Learning System HIGH 7.2
CVE-2025-1590

A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /a…

Mitigation only
Fix from $1,950 2025-02-23
Education And Training System CRITICAL 9.8
CVE-2025-1555

A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. …

Mitigation only
Fix from $2,300 2025-02-21
Cm3 Acora Content Management System MEDIUM 6.0
CVE-2025-25968

DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive infor…

Mitigation only
Fix from $1,600 2025-02-20
Recoverpoint For Virtual Machines HIGH 7.8
CVE-2025-21105

Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could pote…

Mitigation only
Fix from $1,950 2025-02-20
Power Pages CRITICAL 9.8
CVE-2025-24989 KEV

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th…

Patch available
Fix from $2,300 2025-02-19
Unclassified CRITICAL 9.1
CVE-2020-35546

Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.

Mitigation only
Fix from $2,300 2025-02-19
Secure Email Gateway MEDIUM 5.3
CVE-2025-20153

A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configur…

Mitigation only
Fix from $1,600 2025-02-19
Elementskit Elementor Addons MEDIUM 5.3
CVE-2025-0968

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 du…

Fix: 3.4.1+
Fix from $1,600 2025-02-19
Wegia HIGH 7.5
CVE-2025-26616

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the …

Fix: 3.2.14+
Fix from $1,950 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26617

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.14+
Fix from $2,300 2025-02-18