Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Ruoyi HIGH 8.8
CVE-2025-56396

An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the act…

No fix yet
Fix from $1,950 2025-11-26
Ruoyi HIGH 7.5
CVE-2025-46174

Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserControll…

Mitigation only
Fix from $1,950 2025-11-26
Unclassified MEDIUM 5.4
CVE-2025-65963

Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow n…

Patch available
Fix from $1,600 2025-11-26
Project Contract Management HIGH 8.8
CVE-2025-64064

Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SEC…

Mitigation only
Fix from $1,950 2025-11-25
Project Contract Management HIGH 8.6
CVE-2025-64066

Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any…

Mitigation only
Fix from $1,950 2025-11-25
Pingalert Application Server HIGH 7.5
CVE-2025-54563

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Inc…

Fix: 6.1.1.6+
Fix from $1,950 2025-11-24
Pingalert Application Server HIGH 7.5
CVE-2025-54338

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an …

Fix: 6.1.1.6+
Fix from $1,950 2025-11-24
Vision Tools Workspace CRITICAL 9.8
CVE-2025-63958

MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authenticatio…

Mitigation only
Fix from $2,300 2025-11-24
Advanced Library Management System HIGH 8.8
CVE-2025-13573

A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_…

No fix yet
Fix from $1,950 2025-11-24
Online Bidding System HIGH 7.2
CVE-2025-13574

A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/add…

No fix yet
Fix from $1,950 2025-11-24
Travel Agency CRITICAL 9.8
CVE-2025-13544

A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the f…

Fix: after 2025-07-05
Fix from $2,300 2025-11-23
Unclassified MEDIUM 5.3
CVE-2025-64483

Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configurati…

Patch available
Fix from $1,600 2025-11-21
Visual Studio Code HIGH 8.0
CVE-2025-64660

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

Fix: 1.106.2+
Fix from $1,950 2025-11-20
Revive Adserver HIGH 8.8
CVE-2025-48986

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and po…

Fix: after 6.0.1
Fix from $1,950 2025-11-20
Phppgadmin MEDIUM 6.1
CVE-2025-60799

phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manip…

Fix: after 7.13.0
Fix from $1,600 2025-11-20
Mall MEDIUM 6.5
CVE-2025-13443

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Pe…

Fix: after 1.0.3
Fix from $1,600 2025-11-20
Retro Basketball Shoes Online Store HIGH 7.2
CVE-2025-13423

A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_prod…

No fix yet
Fix from $1,950 2025-11-20
Retro Basketball Shoes Online Store CRITICAL 9.8
CVE-2025-13411

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the fil…

Mitigation only
Fix from $2,300 2025-11-19
Vbc Server MEDIUM 6.5
CVE-2025-63214

An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauthorized attackers to delete an…

No fix yet
Fix from $1,600 2025-11-19
Puma Firmware CRITICAL 9.1
CVE-2025-63221

The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi…

Fix: after 1.0.3
Fix from $2,300 2025-11-19
Streamermax Mk Ii Firmware CRITICAL 9.8
CVE-2025-63223

The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authenticatio…

Fix: after 1.0.3
Fix from $2,300 2025-11-19
Wolf1ms Firmware CRITICAL 9.8
CVE-2025-63218

The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authenticat…

Fix: after 1.0.3
Fix from $2,300 2025-11-19
Iso Fm Firmware HIGH 7.5
CVE-2025-63219

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home…

No fix yet
Fix from $1,950 2025-11-19
Elts 100 Firmware CRITICAL 9.8
CVE-2025-63225

The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical admi…

Mitigation only
Fix from $2,300 2025-11-18
Mihomo MEDIUM 6.5
CVE-2025-56499

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges…

No fix yet
Fix from $1,600 2025-11-18
Arubaos Cx HIGH 7.8
CVE-2025-37155

A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only u…

Fix: 10.10.1170 / 10.13.1101+
Fix from $1,950 2025-11-18
Ewio2 M Firmware HIGH 7.5
CVE-2025-41737

Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.

Fix: 2.2.0+
Fix from $1,950 2025-11-18
Datax Web HIGH 8.8
CVE-2025-13250

A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job…

Fix: after 2.1.2
Fix from $1,950 2025-11-16
Unclassified MEDIUM 6.3
CVE-2025-13249

A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTempl…

Mitigation only
Fix from $1,600 2025-11-16
Flight Booking Software HIGH 8.8
CVE-2025-13238

A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/pro…

No fix yet
Fix from $1,950 2025-11-16