Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified MEDIUM 5.6
CVE-2025-14660

A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mc…

Patch available
Fix from $1,600 2025-12-14
Computer Laboratory System HIGH 7.2
CVE-2025-14642

A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. …

No fix yet
Fix from $1,950 2025-12-14
Computer Laboratory System HIGH 7.2
CVE-2025-14641

A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. Th…

No fix yet
Fix from $1,950 2025-12-14
Online Student Enrollment System CRITICAL 9.8
CVE-2025-14583

A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing …

Mitigation only
Fix from $2,300 2025-12-12
Online Student Enrollment System HIGH 7.2
CVE-2025-14582

A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=us…

No fix yet
Fix from $1,950 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43513

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2…

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43416

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app ma…

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43351

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user …

Fix: 26.1+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.2
CVE-2025-43393

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of i…

Fix: 26.1+
Fix from $1,600 2025-12-12
Plesk CRITICAL 9.1
CVE-2025-66430

Plesk 18.0 has Incorrect Access Control.

Fix: 18.0.73.5 / 18.0.74.2+
Fix from $2,300 2025-12-12
Windows Admin Center HIGH 7.8
CVE-2025-64669

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally.

Fix: 2511+
Fix from $1,950 2025-12-11
Real Estate Property Listing App HIGH 7.2
CVE-2025-14530

A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin…

No fix yet
Fix from $1,950 2025-12-11
Dir 803 Firmware HIGH 7.5
CVE-2025-14528

A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Han…

Fix: after 1.04
Fix from $1,950 2025-12-11
Hfly CRITICAL 9.8
CVE-2025-14522

A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /…

Fix: after 2016-05-11
Fix from $2,300 2025-12-11
Neuron CRITICAL 9.4
CVE-2025-67510

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided …

Fix: 2.8.12+
Fix from $2,300 2025-12-10
U Boot HIGH 7.6
CVE-2025-24857

Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018…

Fix: 2017.11+
Fix from $1,950 2025-12-10
Coldfusion MEDIUM 5.6
CVE-2025-64897

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could le…

Mitigation only
Fix from $1,600 2025-12-10
Opensis HIGH 8.1
CVE-2025-65594

OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthori…

Fix: after 9.2
Fix from $1,950 2025-12-09
Windows 10 1809 HIGH 7.8
CVE-2025-64673

Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09
Windows 11 24h2 MEDIUM 5.5
CVE-2025-62570

Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,600 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-62474

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Fortisoar MEDIUM 6.5
CVE-2025-59810

An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all v…

Fix: 7.5.2 / 7.6.3+
Fix from $1,600 2025-12-09
Windows 10 1607 HIGH 7.8
CVE-2025-59517

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Ac9 Firmware HIGH 7.5
CVE-2025-14286

A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/Downlo…

No fix yet
Fix from $1,950 2025-12-09
Memos HIGH 7.5
CVE-2025-65795

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a craf…

Patch available
Fix from $1,950 2025-12-08
Memos MEDIUM 6.5
CVE-2025-65797

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify …

Patch available
Fix from $1,600 2025-12-08
Memos MEDIUM 5.4
CVE-2025-65798

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by oth…

Patch available
Fix from $1,600 2025-12-08
Retro Basketball Shoes Online Store HIGH 7.2
CVE-2025-14219

A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/a…

No fix yet
Fix from $1,950 2025-12-08
Verysync MEDIUM 5.3
CVE-2025-14198

A vulnerability was detected in Verysync 微力同步 2.21.3. This affects an unknown function of the file /safebrowsing/clientreport/download?key=dummyt…

Fix: after 2.21.3
Fix from $1,600 2025-12-07
Verysync CRITICAL 9.8
CVE-2025-14199

A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text…

Fix: after 2.21.3
Fix from $2,300 2025-12-07