Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
News365 HIGH 7.2
CVE-2025-13185

A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. …

Fix: after 7.0.3
Fix from $1,950 2025-11-14
Pingalert Application Server CRITICAL 10.0
CVE-2025-54339

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remo…

Fix: 6.1.1.4+
Fix from $2,300 2025-11-14
Pingalert Application Server CRITICAL 9.6
CVE-2025-54343

An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remo…

Fix: 6.1.1.4+
Fix from $2,300 2025-11-14
Directus MEDIUM 5.4
CVE-2025-64746

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-…

Fix: 11.13.0+
Fix from $1,600 2025-11-13
Signserver MEDIUM 5.3
CVE-2025-47220

A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in…

Fix: 7.3.1+
Fix from $1,600 2025-11-13
Signserver MEDIUM 5.3
CVE-2025-47221

An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_…

Fix: 7.3.1+
Fix from $1,600 2025-11-13
Signserver MEDIUM 6.5
CVE-2025-47222

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring …

Fix: 7.3.1+
Fix from $1,600 2025-11-13
Alienware Command Center MEDIUM 5.5
CVE-2025-46362

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain an Improper Access Control vulnerability. A low privileged attacker wi…

Fix: 6.10.15.0+
Fix from $1,600 2025-11-13
Compressor HIGH 8.8
CVE-2025-43515

The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauthenticated user on the same ne…

Fix: 4.11.1+
Fix from $1,950 2025-11-13
Typebot HIGH 7.5
CVE-2025-64706

Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerabil…

Fix: 3.13.0+
Fix from $1,950 2025-11-13
Unclassified HIGH 8.8
CVE-2025-20341

A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an…

Mitigation only
Fix from $1,950 2025-11-13
Data Lakehouse HIGH 7.2
CVE-2025-46608

Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access co…

Fix: 1.6.0.0+
Fix from $1,950 2025-11-12
Online Voting System HIGH 8.8
CVE-2025-13061

A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Pe…

No fix yet
Fix from $1,950 2025-11-12
Hg6145f1 Firmware CRITICAL 9.8
CVE-2025-63353

A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted fr…

Mitigation only
Fix from $2,300 2025-11-12
Ac15 Firmware CRITICAL 9.8
CVE-2025-63666

Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suf…

Mitigation only
Fix from $2,300 2025-11-12
Ip Camera Firmware HIGH 7.5
CVE-2025-63667

Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API en…

Mitigation only
Fix from $1,950 2025-11-12
Windows 10 1607 HIGH 7.8
CVE-2025-60705

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.8
CVE-2025-59512

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Configuration Manager 2403 MEDIUM 6.7
CVE-2025-47179

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.

Fix: 5.00.9128.1037 / 5.00.9132.1031+
Fix from $1,600 2025-11-11
Unclassified MEDIUM 6.7
CVE-2025-22391

Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged so…

No fix yet
Fix from $1,600 2025-11-11
Busybox MEDIUM 6.5
CVE-2025-60876

BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request lin…

Fix: after 1.37.0
Fix from $1,600 2025-11-10
Triofox CRITICAL 9.1
CVE-2025-12480 KEVEPSS 91%

Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after se…

Fix: 16.7.10368.56560+
Fix from $2,300 2025-11-10
Unclassified HIGH 7.5
CVE-2025-64347

Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and bel…

Patch available
Fix from $1,950 2025-11-07
Online Notes Sharing Platform CRITICAL 9.8
CVE-2025-12862

A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /…

Mitigation only
Fix from $2,300 2025-11-07
Personmanage MEDIUM 6.5
CVE-2025-63686

There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the …

Fix: after 1.0
Fix from $1,600 2025-11-07
Anydesk HIGH 8.2
CVE-2025-27919

An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk set…

Fix: after 9.0.4
Fix from $1,950 2025-11-06
Devolutions Server MEDIUM 6.5
CVE-2025-12808

Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values,…

Fix: 2025.2.17.0 / 2025.3.6.0+
Fix from $1,600 2025-11-06
Voluntary Like System MEDIUM 6.5
CVE-2025-60784

A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.php Pay m…

No fix yet
Fix from $1,600 2025-11-05
Zwiicms HIGH 8.8
CVE-2025-57130

An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escal…

Fix: after 13.6.07
Fix from $1,950 2025-11-05
Doris Mcp Server MEDIUM 5.4
CVE-2025-58337

An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that s…

Fix: 0.6.0+
Fix from $1,600 2025-11-05