Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Wegia CRITICAL 9.8
CVE-2025-26609

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26611

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26613

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered …

Fix: 3.2.14+
Fix from $2,300 2025-02-18
Wegia HIGH 7.5
CVE-2025-26615

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the …

Fix: 3.2.14+
Fix from $1,950 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26606

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26607

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Wegia CRITICAL 9.8
CVE-2025-26608

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…

Fix: 3.2.13+
Fix from $2,300 2025-02-18
Sage Dpw HIGH 8.1
CVE-2024-56883

Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the serv…

Fix: 2024_12_001+
Fix from $1,950 2025-02-18
Unclassified CRITICAL 9.9
CVE-2024-39327

Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.

Mitigation only
Fix from $2,300 2025-02-18
Unclassified MEDIUM 6.1
CVE-2025-1390

The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@”…

Mitigation only
Fix from $1,600 2025-02-18
Unclassified MEDIUM 5.4
CVE-2025-1391

A flaw was found in the Keycloak organization feature, which allows the incorrect assignment of an organization to a user if their username or email …

Patch available
Fix from $1,600 2025-02-17
Library Card System CRITICAL 9.8
CVE-2025-1355

A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functi…

No fix yet
Fix from $2,300 2025-02-16
Unclassified HIGH 7.3
CVE-2024-57378

Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without …

Mitigation only
Fix from $1,950 2025-02-13
Unclassified MEDIUM 5.9
CVE-2024-41934

Improper access control in some Intel(R) GPA software before version 2024.3 may allow an authenticated user to potentially enable denial of service v…

Mitigation only
Fix from $1,600 2025-02-12
Unclassified MEDIUM 6.5
CVE-2024-39797

Improper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to pot…

Mitigation only
Fix from $1,600 2025-02-12
Unclassified MEDIUM 6.5
CVE-2024-36293

Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentia…

Mitigation only
Fix from $1,600 2025-02-12
Unclassified HIGH 8.8
CVE-2024-37355

Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local ac…

Mitigation only
Fix from $1,950 2025-02-12
Unclassified HIGH 8.2
CVE-2024-38310

Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of priv…

Mitigation only
Fix from $1,950 2025-02-12
Unclassified MEDIUM 6.0
CVE-2024-30211

Improper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potentially en…

Mitigation only
Fix from $1,600 2025-02-12
Unclassified HIGH 7.3
CVE-2023-29164

Improper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP, before v…

Mitigation only
Fix from $1,950 2025-02-12
Commerce B2b MEDIUM 6.5
CVE-2025-24426

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability th…

Fix: 1.3.3+
Fix from $1,600 2025-02-11
Commerce MEDIUM 6.5
CVE-2025-24427

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability th…

Fix: 1.3.3 / 2.4.4+
Fix from $1,600 2025-02-11
Commerce B2b MEDIUM 6.5
CVE-2025-24422

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability th…

Fix: 1.3.3+
Fix from $1,600 2025-02-11
Commerce B2b MEDIUM 6.5
CVE-2025-24424

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability th…

Fix: 1.3.3+
Fix from $1,600 2025-02-11
Commerce HIGH 8.1
CVE-2025-24411

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability th…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2025-02-11
Visual Studio Code HIGH 7.3
CVE-2025-24042

Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability

Fix: 1.97.1+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 7.8
CVE-2025-21359

Windows Kernel Security Feature Bypass Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Forticlient MEDIUM 6.7
CVE-2024-40586

An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow …

Fix: 7.0.14 / 7.2.7+
Fix from $1,600 2025-02-11
Food Menu Manager HIGH 8.8
CVE-2025-1166

A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown funct…

No fix yet
Fix from $1,950 2025-02-11
Unclassified HIGH 7.3
CVE-2025-1165

A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUpl…

Mitigation only
Fix from $1,950 2025-02-11