Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
W18e Firmware MEDIUM 6.5
CVE-2024-46430

Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthent…

No fix yet
Fix from $1,600 2025-02-10
W18e Firmware HIGH 8.8
CVE-2024-46432

Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgW…

No fix yet
Fix from $1,950 2025-02-10
Rt Thread MEDIUM 5.5
CVE-2025-1115

A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the function sys_device_close/sys_dev…

Fix: after 5.1.0
Fix from $1,600 2025-02-08
Unclassified HIGH 7.7
CVE-2022-26389

An improper access control vulnerability may allow privilege escalation.This issue affects:  * ELI 380 Resting Electrocardiograph: Versions 2.6.…

Mitigation only
Fix from $1,950 2025-02-07
Filevista MEDIUM 6.5
CVE-2024-57249

Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a …

No fix yet
Fix from $1,600 2025-02-07
Complaint Management System HIGH 7.5
CVE-2024-56889

Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrari…

No fix yet
Fix from $1,950 2025-02-06
Rengine HIGH 8.8
CVE-2025-24968

reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific …

Fix: after 2.2.0
Fix from $1,950 2025-02-04
Wazuh HIGH 7.8
CVE-2024-35177

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premise…

Fix: 4.9.0+
Fix from $1,950 2025-02-03
Unclassified HIGH 8.8
CVE-2024-56898

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform action…

Mitigation only
Fix from $1,950 2025-02-03
Unclassified MEDIUM 5.1
CVE-2023-52164

access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no …

Mitigation only
Fix from $1,600 2025-02-03
Mall Tiny HIGH 7.5
CVE-2024-57433

macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available a…

No fix yet
Fix from $1,950 2025-01-31
Home Flex Nema 14 50 Plug Firmware HIGH 8.8
CVE-2024-23920

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. …

Mitigation only
Fix from $1,950 2025-01-31
Unclassified HIGH 7.6
CVE-2025-24885

pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rende…

Mitigation only
Fix from $1,950 2025-01-30
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2025-23367

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured usin…

Fix: 7.4.21 / 8.0.7+
Fix from $1,600 2025-01-30
Embedai MEDIUM 6.5
CVE-2025-0742

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files…

Fix: 2.1+
Fix from $1,600 2025-01-30
Embedai MEDIUM 6.5
CVE-2025-0744

an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subs…

Fix: 2.1+
Fix from $1,600 2025-01-30
Embedai MEDIUM 6.5
CVE-2025-0745

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the b…

Fix: 2.1+
Fix from $1,600 2025-01-30
Embedai MEDIUM 6.5
CVE-2025-0739

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscri…

Fix: 2.1+
Fix from $1,600 2025-01-30
Embedai MEDIUM 6.5
CVE-2025-0740

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain cha…

Fix: 2.1+
Fix from $1,600 2025-01-30
Event Tickets MEDIUM 5.3
CVE-2024-13457

The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.…

Fix: 5.18.1.1+
Fix from $1,600 2025-01-30
Best Employee Management System HIGH 8.1
CVE-2025-0802

A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown …

No fix yet
Fix from $1,950 2025-01-29
Unclassified MEDIUM 6.3
CVE-2025-0783

A vulnerability, which was classified as problematic, was found in pankajindevops scale up to 20241113. This affects an unknown part of the component…

Mitigation only
Fix from $1,600 2025-01-28
Vaultwarden HIGH 7.5
CVE-2025-24365

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other o…

Fix: 1.33.0+
Fix from $1,950 2025-01-27
Image Gallery Management System HIGH 7.2
CVE-2025-0722

A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.p…

No fix yet
Fix from $1,950 2025-01-27
Bootplus HIGH 8.8
CVE-2025-0702

A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This vulnerability affects unk…

Fix: after 2020-08-24
Fix from $1,950 2025-01-24
Unclassified HIGH 8.1
CVE-2025-0650

A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations …

Mitigation only
Fix from $1,950 2025-01-23
Unclassified HIGH 7.7
CVE-2025-23083

With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers…

Mitigation only
Fix from $1,950 2025-01-22
Unclassified MEDIUM 5.5
CVE-2024-57360

https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm …

Mitigation only
Fix from $1,600 2025-01-21
Tailoring Management System HIGH 7.2
CVE-2025-0582

A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability affects unknown code of the fil…

No fix yet
Fix from $1,950 2025-01-20
Edge Chromium MEDIUM 6.5
CVE-2025-21185

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 132.0.2957.115+
Fix from $1,600 2025-01-17