Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Safari MEDIUM 5.5
CVE-2025-46282

The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app may be able to access sensit…

Fix: 26.2+
Fix from $1,600 2025-12-17
Churchcrm HIGH 8.3
CVE-2025-66397

ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk func…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Unclassified MEDIUM 6.8
CVE-2025-14095

A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user …

Mitigation only
Fix from $1,600 2025-12-17
Unclassified HIGH 7.0
CVE-2025-11901

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z59…

Mitigation only
Fix from $1,950 2025-12-17
Tc155 Firmware MEDIUM 5.4
CVE-2025-14748

A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVI…

No fix yet
Fix from $1,600 2025-12-16
Tc155 Firmware HIGH 8.8
CVE-2025-14749

A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVI…

No fix yet
Fix from $1,950 2025-12-16
A3300r Firmware CRITICAL 9.1
CVE-2025-55895

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Atta…

No fix yet
Fix from $2,300 2025-12-15
Oneagent HIGH 7.5
CVE-2025-65176

An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a machine where OneAgent is inst…

Fix: 1.325.47+
Fix from $1,950 2025-12-15
Wekan HIGH 7.5
CVE-2025-65779

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a boar…

Fix: 8.16+
Fix from $1,950 2025-12-15
Wekan HIGH 8.8
CVE-2025-65780

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire…

Fix: 8.16+
Fix from $1,950 2025-12-15
Unclassified MEDIUM 5.6
CVE-2025-14660

A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mc…

Patch available
Fix from $1,600 2025-12-14
Computer Laboratory System HIGH 7.2
CVE-2025-14642

A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. …

No fix yet
Fix from $1,950 2025-12-14
Computer Laboratory System HIGH 7.2
CVE-2025-14641

A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. Th…

No fix yet
Fix from $1,950 2025-12-14
Online Student Enrollment System CRITICAL 9.8
CVE-2025-14583

A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing …

Mitigation only
Fix from $2,300 2025-12-12
Online Student Enrollment System HIGH 7.2
CVE-2025-14582

A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=us…

No fix yet
Fix from $1,950 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43513

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2…

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43416

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app ma…

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43351

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user …

Fix: 26.1+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.2
CVE-2025-43393

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of i…

Fix: 26.1+
Fix from $1,600 2025-12-12
Plesk CRITICAL 9.1
CVE-2025-66430

Plesk 18.0 has Incorrect Access Control.

Fix: 18.0.73.5 / 18.0.74.2+
Fix from $2,300 2025-12-12
Windows Admin Center HIGH 7.8
CVE-2025-64669

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2511+
Fix from $1,950 2025-12-11
Real Estate Property Listing App HIGH 7.2
CVE-2025-14530

A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin…

No fix yet
Fix from $1,950 2025-12-11
Dir 803 Firmware HIGH 7.5
CVE-2025-14528

A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Han…

Fix: after 1.04
Fix from $1,950 2025-12-11
Hfly CRITICAL 9.8
CVE-2025-14522

A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /…

Fix: after 2016-05-11
Fix from $2,300 2025-12-11
Neuron CRITICAL 9.4
CVE-2025-67510

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided …

Fix: 2.8.12+
Fix from $2,300 2025-12-10
U Boot HIGH 7.6
CVE-2025-24857

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018…

Fix: 2017.11+
Fix from $1,950 2025-12-10
Coldfusion MEDIUM 5.6
CVE-2025-64897

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could le…

Mitigation only
Fix from $1,600 2025-12-10
Opensis HIGH 8.1
CVE-2025-65594

OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthori…

Fix: after 9.2
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-64673

Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 11 24h2 MEDIUM 5.5
CVE-2025-62570

Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,600 2025-12-09