Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified HIGH 7.5
CVE-2025-61115

ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed by ABC Liquors, Inc., contai…

Mitigation only
Fix from $1,950 2025-10-30
Unclassified HIGH 7.5
CVE-2025-61116

AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arshad, contains an improper acce…

Mitigation only
Fix from $1,950 2025-10-30
Unclassified HIGH 7.5
CVE-2025-61117

Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an improper access control vulnerabil…

Mitigation only
Fix from $1,950 2025-10-30
Unclassified HIGH 7.5
CVE-2025-61118

mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper access control vulnerabilities. At…

Mitigation only
Fix from $1,950 2025-10-30
Unclassified CRITICAL 9.8
CVE-2025-43027

A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attackers to gain administrative a…

Mitigation only
Fix from $2,300 2025-10-30
Unclassified HIGH 7.5
CVE-2025-61234

Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local network without authentication. Thi…

Mitigation only
Fix from $1,950 2025-10-29
Unclassified HIGH 7.8
CVE-2025-61156

Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary co…

Mitigation only
Fix from $1,950 2025-10-29
Unclassified MEDIUM 6.3
CVE-2025-27093

Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev…

Patch available
Fix from $1,600 2025-10-28
Jsherp HIGH 7.5
CVE-2025-60800

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via …

Fix: 2025-08-07+
Fix from $1,950 2025-10-28
Unclassified HIGH 7.5
CVE-2025-60354

Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.

Mitigation only
Fix from $1,950 2025-10-28
Simple Food Ordering System CRITICAL 9.8
CVE-2025-12378

A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addprod…

Mitigation only
Fix from $2,300 2025-10-28
Maxsite Cms HIGH 8.8
CVE-2025-12347

A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files…

Fix: after 109
Fix from $1,950 2025-10-28
Maxsite Cms HIGH 8.8
CVE-2025-12346

A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_pos…

Fix: after 109
Fix from $1,950 2025-10-28
Unclassified MEDIUM 6.3
CVE-2025-12344

A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /service/NCloudGatewayServlet …

Mitigation only
Fix from $1,600 2025-10-28
Willow Cms HIGH 7.2
CVE-2025-12331

A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unr…

Fix: after 1.4.0
Fix from $1,950 2025-10-27
Unclassified MEDIUM 5.4
CVE-2025-60982

IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object references. Affected endpoints…

Mitigation only
Fix from $1,600 2025-10-27
Simple Food Ordering System CRITICAL 9.8
CVE-2025-12301

A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct…

Mitigation only
Fix from $2,300 2025-10-27
Socet Gxp HIGH 8.8
CVE-2025-54968

An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may …

Fix: 4.6.0.2+
Fix from $1,950 2025-10-27
Socet Gxp MEDIUM 6.5
CVE-2025-54970

An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, thi…

Fix: 4.6.0.2+
Fix from $1,600 2025-10-27
Unclassified MEDIUM 5.3
CVE-2023-37749

Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorizati…

Mitigation only
Fix from $1,600 2025-10-27
Unclassified CRITICAL 9.1
CVE-2025-60291

An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access s…

Mitigation only
Fix from $2,300 2025-10-27
Learnhouse HIGH 7.5
CVE-2025-12276

A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of th…

Fix: after 2025-09-21
Fix from $1,950 2025-10-27
Learnhouse CRITICAL 9.8
CVE-2025-12268

A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/cour…

Fix: after 2025-09-21
Fix from $2,300 2025-10-27
Flight Booking Software HIGH 8.8
CVE-2025-12223

A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the co…

Fix: after 3.1
Fix from $1,950 2025-10-27
Flight Booking Software HIGH 8.8
CVE-2025-12222

A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some unknown functionality of the f…

Fix: after 3.1
Fix from $1,950 2025-10-27
User Management Php Mysql HIGH 7.2
CVE-2025-12201

A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This affects an unknown part…

Fix: after 2023-03-16
Fix from $1,950 2025-10-27
Azure Notification Service HIGH 8.8
CVE-2025-59500

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-10-23
Azure Event Grid CRITICAL 9.8
CVE-2025-59273

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-10-23
Unclassified HIGH 7.2
CVE-2025-62713

Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE…

Patch available
Fix from $1,950 2025-10-23
Zfs Storage Appliance Kit HIGH 7.2
CVE-2025-62290

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected …

Mitigation only
Fix from $1,950 2025-10-21