Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Content Management System CRITICAL 9.8
CVE-2026-0566

A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_po…

Mitigation only
Fix from $2,300 2026-01-02
Online Course Registration HIGH 8.8
CVE-2026-0547

A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-stud…

Fix: after 3.1
Fix from $1,950 2026-01-02
Unclassified HIGH 7.3
CVE-2025-15426

A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/webuploader/0.1.5/server/previe…

No fix yet
Fix from $1,950 2026-01-02
Empirecms HIGH 8.8
CVE-2025-15423

A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Suc…

Fix: after 8.0
Fix from $1,950 2026-01-02
Wangmarket MEDIUM 5.4
CVE-2025-15415

A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the…

Fix: after 6.4
Fix from $1,600 2026-01-01
School File Management System HIGH 8.8
CVE-2025-15404

A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /s…

No fix yet
Fix from $1,950 2026-01-01
Newbee Mall Plus HIGH 7.2
CVE-2025-15360

A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd/newbee/mall/controller/commo…

No fix yet
Fix from $1,950 2025-12-30
Unclassified MEDIUM 6.7
CVE-2025-69257

theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loa…

Patch available
Fix from $1,600 2025-12-30
Simple Php Cms HIGH 7.2
CVE-2025-15262

A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/edit.php of the component S…

No fix yet
Fix from $1,950 2025-12-30
Unclassified MEDIUM 5.4
CVE-2023-32238

Vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery).This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem…

No fix yet
Fix from $1,600 2025-12-30
College Notes Uploading System HIGH 8.8
CVE-2025-15199

A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboar…

Mitigation only
Fix from $1,950 2025-12-29
News Buzz HIGH 7.2
CVE-2025-15197

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown co…

No fix yet
Fix from $1,950 2025-12-29
Unclassified MEDIUM 6.3
CVE-2025-15152

A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability affects the function addProduc…

Mitigation only
Fix from $1,600 2025-12-28
Xcms HIGH 7.2
CVE-2025-15110

A vulnerability has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. Affected is the function Upload of the file Admin/Home/C…

No fix yet
Fix from $1,950 2025-12-27
Unclassified HIGH 7.3
CVE-2025-15109

A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of the file Public/javascripts/a…

Mitigation only
Fix from $1,950 2025-12-27
Dev7113 Firmware HIGH 7.5
CVE-2025-67014

Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access…

No fix yet
Fix from $1,950 2025-12-26
Cdm 625 Firmware HIGH 7.5
CVE-2025-67015

Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administr…

No fix yet
Fix from $1,950 2025-12-26
Zlt M30s Firmware HIGH 7.5
CVE-2025-15082

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Managemen…

Fix: after 1.47
Fix from $1,950 2025-12-25
Student File Management System HIGH 8.8
CVE-2025-15050

A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.p…

No fix yet
Fix from $1,950 2025-12-24
Youlai Boot HIGH 7.5
CVE-2025-66735

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks,…

Patch available
Fix from $1,950 2025-12-22
Youlai Boot HIGH 7.1
CVE-2025-66736

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check…

Patch available
Fix from $1,950 2025-12-22
Gt Edge Ai HIGH 7.5
CVE-2025-63663

Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other…

Fix: 2.0.12+
Fix from $1,950 2025-12-22
Gt Edge Ai HIGH 7.5
CVE-2025-63664

Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to acces…

Fix: 2.0.12+
Fix from $1,950 2025-12-22
Chestnutcms HIGH 8.8
CVE-2025-15009

A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/com…

Fix: after 1.5.8
Fix from $1,950 2025-12-22
Turms MEDIUM 6.5
CVE-2025-66911

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handle…

No fix yet
Fix from $1,600 2025-12-19
Dify HIGH 7.5
CVE-2025-63387EPSS 30%

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-feature…

Patch available
Fix from $1,950 2025-12-18
Client Database Management System HIGH 8.8
CVE-2025-14885

A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the compon…

No fix yet
Fix from $1,950 2025-12-18
Drivelock MEDIUM 5.3
CVE-2025-67789

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer co…

Fix: 24.1.6 / 24.2.7+
Fix from $1,600 2025-12-17
Ipados MEDIUM 5.5
CVE-2025-46288

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, wat…

Fix: 26.2+
Fix from $1,600 2025-12-17
Ipados MEDIUM 5.5
CVE-2025-46292

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app ma…

Fix: 18.7.3 / 26.2+
Fix from $1,600 2025-12-17