Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
College Notes Uploading System HIGH 8.8
CVE-2025-15199

A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboar…

Mitigation only
Fix from $1,950 2025-12-29
News Buzz HIGH 7.2
CVE-2025-15197

A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown co…

No fix yet
Fix from $1,950 2025-12-29
Unclassified MEDIUM 6.3
CVE-2025-15152

A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability affects the function addProduc…

Mitigation only
Fix from $1,600 2025-12-28
Xcms HIGH 7.2
CVE-2025-15110

A vulnerability has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. Affected is the function Upload of the file Admin/Home/C…

No fix yet
Fix from $1,950 2025-12-27
Unclassified HIGH 7.3
CVE-2025-15109

A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of the file Public/javascripts/a…

Mitigation only
Fix from $1,950 2025-12-27
Dev7113 Firmware HIGH 7.5
CVE-2025-67014

Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access…

No fix yet
Fix from $1,950 2025-12-26
Cdm 625 Firmware HIGH 7.5
CVE-2025-67015

Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administr…

No fix yet
Fix from $1,950 2025-12-26
Zlt M30s Firmware HIGH 7.5
CVE-2025-15082

A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Managemen…

Fix: after 1.47
Fix from $1,950 2025-12-25
Student File Management System HIGH 8.8
CVE-2025-15050

A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.p…

No fix yet
Fix from $1,950 2025-12-24
Youlai Boot HIGH 7.5
CVE-2025-66735

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks,…

Patch available
Fix from $1,950 2025-12-22
Youlai Boot HIGH 7.1
CVE-2025-66736

youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check…

Patch available
Fix from $1,950 2025-12-22
Gt Edge Ai HIGH 7.5
CVE-2025-63663

Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other…

Fix: 2.0.12+
Fix from $1,950 2025-12-22
Gt Edge Ai HIGH 7.5
CVE-2025-63664

Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to acces…

Fix: 2.0.12+
Fix from $1,950 2025-12-22
Chestnutcms HIGH 8.8
CVE-2025-15009

A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/com…

Fix: after 1.5.8
Fix from $1,950 2025-12-22
Turms MEDIUM 6.5
CVE-2025-66911

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handle…

No fix yet
Fix from $1,600 2025-12-19
Dify HIGH 7.5
CVE-2025-63387EPSS 30%

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-feature…

Patch available
Fix from $1,950 2025-12-18
Client Database Management System HIGH 8.8
CVE-2025-14885

A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the compon…

No fix yet
Fix from $1,950 2025-12-18
Drivelock MEDIUM 5.3
CVE-2025-67789

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer co…

Fix: 24.1.6 / 24.2.7+
Fix from $1,600 2025-12-17
Ipados MEDIUM 5.5
CVE-2025-46288

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, wat…

Fix: 26.2+
Fix from $1,600 2025-12-17
Ipados MEDIUM 5.5
CVE-2025-46292

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app ma…

Fix: 18.7.3 / 26.2+
Fix from $1,600 2025-12-17
Safari MEDIUM 5.5
CVE-2025-46282

The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app may be able to access sensit…

Fix: 26.2+
Fix from $1,600 2025-12-17
Churchcrm HIGH 8.3
CVE-2025-66397

ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk func…

Fix: 6.5.3+
Fix from $1,950 2025-12-17
Unclassified MEDIUM 6.8
CVE-2025-14095

A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user …

Mitigation only
Fix from $1,600 2025-12-17
Unclassified HIGH 7.0
CVE-2025-11901

An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z59…

Mitigation only
Fix from $1,950 2025-12-17
Tc155 Firmware MEDIUM 5.4
CVE-2025-14748

A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVI…

No fix yet
Fix from $1,600 2025-12-16
Tc155 Firmware HIGH 8.8
CVE-2025-14749

A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVI…

No fix yet
Fix from $1,950 2025-12-16
A3300r Firmware CRITICAL 9.1
CVE-2025-55895

TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Atta…

No fix yet
Fix from $2,300 2025-12-15
Oneagent HIGH 7.5
CVE-2025-65176

An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a machine where OneAgent is inst…

Fix: 1.325.47+
Fix from $1,950 2025-12-15
Wekan HIGH 7.5
CVE-2025-65779

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a boar…

Fix: 8.16+
Fix from $1,950 2025-12-15
Wekan HIGH 8.8
CVE-2025-65780

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire…

Fix: 8.16+
Fix from $1,950 2025-12-15