Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified MEDIUM 5.3
CVE-2025-14197

A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/res…

Mitigation only
Fix from $1,600 2025-12-07
Employee Profile Management System HIGH 8.8
CVE-2025-14195

A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/a…

No fix yet
Fix from $1,950 2025-12-07
Youlai Mall HIGH 8.8
CVE-2025-14086

A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipul…

No fix yet
Fix from $1,950 2025-12-05
Youlai Mall MEDIUM 6.5
CVE-2025-14052

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-…

No fix yet
Fix from $1,600 2025-12-05
Lara Dashboard CRITICAL 9.8
CVE-2025-66509

LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowin…

Fix: after 2.3.0
Fix from $2,300 2025-12-04
Rs232\/485 To Wifi Eth \(b\) Firmware HIGH 7.5
CVE-2025-63363

A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage …

No fix yet
Fix from $1,950 2025-12-04
Platform HIGH 7.5
CVE-2025-57210

Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspecified v…

Mitigation only
Fix from $1,950 2025-12-04
Platform HIGH 7.5
CVE-2025-57212

Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a crafted requ…

Mitigation only
Fix from $1,950 2025-12-04
Platform HIGH 7.5
CVE-2025-57213

Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via a crafted …

Mitigation only
Fix from $1,950 2025-12-04
Romm MEDIUM 6.5
CVE-2025-65097

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4…

Fix: 4.4.1+
Fix from $1,600 2025-12-03
Aquarius MEDIUM 6.2
CVE-2025-65841

Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings …

No fix yet
Fix from $1,600 2025-12-03
Unclassified MEDIUM 6.3
CVE-2025-13949

A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.…

Mitigation only
Fix from $1,600 2025-12-03
Nshield 5c Firmware CRITICAL 9.1
CVE-2025-59703

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal compo…

Fix: 13.6.12 / 13.9.0+
Fix from $2,300 2025-12-02
Nshield 5c Firmware HIGH 7.2
CVE-2025-59697

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by ed…

Fix: 13.6.12 / 13.9.0+
Fix from $1,950 2025-12-02
Nshield 5c Firmware HIGH 7.2
CVE-2025-59702

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with elevated privileges to …

Fix: 13.6.12 / 13.9.0+
Fix from $1,950 2025-12-02
Xwiki HIGH 7.5
CVE-2025-55749

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJ…

Fix: 16.10.11 / 17.4.4+
Fix from $1,950 2025-12-01
Superduper\! HIGH 7.8
CVE-2025-61229

An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight …

Fix: after 3.10
Fix from $1,950 2025-12-01
Superduper\! HIGH 8.1
CVE-2025-57489

Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improp…

Mitigation only
Fix from $1,950 2025-12-01
Blood Bank Management System HIGH 8.8
CVE-2025-63525

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted…

No fix yet
Fix from $1,950 2025-12-01
Mogublog CRITICAL 9.8
CVE-2025-13815

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This man…

Fix: after 5.2
Fix from $2,300 2025-12-01
Skuul MEDIUM 6.5
CVE-2025-13785

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the …

Fix: after 2.6.5
Fix from $1,600 2025-11-30
Unclassified HIGH 8.4
CVE-2025-66223

OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid…

Mitigation only
Fix from $1,950 2025-11-29
Rallly MEDIUM 6.5
CVE-2025-66027

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant detai…

Fix: 4.5.6+
Fix from $1,600 2025-11-29
Cilium MEDIUM 5.5
CVE-2025-64715

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetw…

Fix: 1.16.17 / 1.17.10+
Fix from $1,600 2025-11-29
Hashtech CRITICAL 9.8
CVE-2025-65276

An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru comm…

Fix: after 2021-07-02
Fix from $2,300 2025-11-26
Oneuptime HIGH 8.2
CVE-2025-66028

OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via L…

Fix: 8.0.5567+
Fix from $1,950 2025-11-26
Youlai Boot CRITICAL 9.8
CVE-2025-55469

Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

Mitigation only
Fix from $2,300 2025-11-26
Youlai Boot HIGH 7.5
CVE-2025-55471

Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.

No fix yet
Fix from $1,950 2025-11-26
Ussd Gateway MEDIUM 6.5
CVE-2025-65238

Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with l…

No fix yet
Fix from $1,600 2025-11-26
Ruoyi HIGH 7.5
CVE-2025-46175

Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserContr…

Mitigation only
Fix from $1,950 2025-11-26