Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Cursor HIGH 7.5
CVE-2025-64110

Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive files tha…

Fix: 2.0+
Fix from $1,950 2025-11-05
Linkace MEDIUM 6.5
CVE-2025-62721

LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints in the FeedController class …

Fix: 2.4.0+
Fix from $1,600 2025-11-04
Linkace MEDIUM 6.5
CVE-2025-62720

LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to export the entire database of lin…

Fix: 2.4.0+
Fix from $1,600 2025-11-04
Safari HIGH 7.5
CVE-2025-43502

A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26…

Fix: 26.1+
Fix from $1,950 2025-11-04
macOS HIGH 7.8
CVE-2025-43476

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A…

Fix: 14.8.2 / 15.7.2+
Fix from $1,950 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43477

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.2
CVE-2025-43481

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to break out of its …

Fix: 15.7.2+
Fix from $1,600 2025-11-04
Ipados MEDIUM 5.4
CVE-2025-43495

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to mo…

Fix: 26.1+
Fix from $1,600 2025-11-04
Ipados MEDIUM 5.5
CVE-2025-43498

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Son…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43499

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS Sequoia 15.7.2, macOS Sonoma …

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
Ipados HIGH 7.5
CVE-2025-43450

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able t…

Fix: 26.1+
Fix from $1,950 2025-11-04
Ipados HIGH 7.5
CVE-2025-43454

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. A device m…

Fix: 26.1+
Fix from $1,950 2025-11-04
Ipados HIGH 7.8
CVE-2025-43407

This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.…

Fix: 14.8.2 / 15.7.2+
Fix from $1,950 2025-11-04
macOS MEDIUM 6.3
CVE-2025-43412

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
Safari HIGH 7.5
CVE-2025-43413

An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sono…

Fix: 14.8.2 / 15.7.2+
Fix from $1,950 2025-11-04
macOS MEDIUM 6.2
CVE-2025-43414

A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A sho…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43396

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A sandboxed app…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43334

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An a…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43335

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS MEDIUM 5.5
CVE-2025-43322

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be a…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
Simple Online Hotel Reservation System HIGH 7.2
CVE-2025-12593

A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The impacted element is an unknown function of the file /…

No fix yet
Fix from $1,950 2025-11-02
Vacation Rental Management Platform MEDIUM 6.3
CVE-2025-63562

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers c…

Fix: 1.0.2+
Fix from $1,600 2025-10-31
Unclassified CRITICAL 10.0
CVE-2025-29270

Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1.0 to v1.1.26 allows attackers to gain access to the…

Mitigation only
Fix from $2,300 2025-10-31
Veeam Backup \& Replication CRITICAL 9.9
CVE-2025-48983

A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts b…

Fix: 12.3.2.4165+
Fix from $2,300 2025-10-31
Unclassified HIGH 7.5
CVE-2025-63423

Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password.

Mitigation only
Fix from $1,950 2025-10-30
Unclassified HIGH 7.5
CVE-2025-63422

Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers…

Mitigation only
Fix from $1,950 2025-10-30
Unclassified HIGH 7.5
CVE-2025-61114

2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., contains an improper access cont…

Mitigation only
Fix from $1,950 2025-10-30
Unclassified HIGH 7.5
CVE-2025-61119

Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access control vulnerabilities. Attacker…

Mitigation only
Fix from $1,950 2025-10-30
Unclassified HIGH 7.5
CVE-2025-61120

AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., contains improper access control…

Mitigation only
Fix from $1,950 2025-10-30
Unclassified HIGH 7.5
CVE-2025-61113

TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API endpoints. By modifying request parameters, attackers may…

Mitigation only
Fix from $1,950 2025-10-30