Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Windows 10 1507 HIGH 7.8
CVE-2025-59230 KEV

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.8
CVE-2025-59199

Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.7919 / 10.0.19044.6456+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-59201

Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.5
CVE-2025-58726

Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Azure Connected Machine Agent HIGH 7.8
CVE-2025-58724

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.57+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.8
CVE-2025-58714

Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 11 24h2 HIGH 7.8
CVE-2025-55694

Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.6899 / 10.0.26200.6899+
Fix from $1,950 2025-10-14
Unclassified MEDIUM 6.5
CVE-2025-54603

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of exist…

Mitigation only
Fix from $1,600 2025-10-14
Visual Studio 2017 HIGH 7.3
CVE-2025-55240

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

Fix: 15.9.77 / 16.11.52+
Fix from $1,950 2025-10-14
Azure Connected Machine Agent HIGH 7.0
CVE-2025-47989

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.57+
Fix from $1,950 2025-10-14
Arubaos MEDIUM 6.5
CVE-2025-37135

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful expl…

Fix: 8.10.0.19 / 8.12.0.6+
Fix from $1,600 2025-10-14
Arubaos MEDIUM 6.5
CVE-2025-37136

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful expl…

Fix: 8.10.0.19 / 8.12.0.6+
Fix from $1,600 2025-10-14
Arubaos MEDIUM 6.5
CVE-2025-37137

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful expl…

Fix: 8.10.0.19 / 8.12.0.6+
Fix from $1,600 2025-10-14
Powershell HIGH 7.3
CVE-2025-25004

Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

Fix: 7.4.13 / 7.5.4+
Fix from $1,950 2025-10-14
Unclassified MEDIUM 6.0
CVE-2025-0033

Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially result…

Mitigation only
Fix from $1,600 2025-10-14
Firefox MEDIUM 6.5
CVE-2025-11716

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 1…

Fix: 144.0+
Fix from $1,600 2025-10-14
Network Manager CRITICAL 9.8
CVE-2025-27258

Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.

Fix: 25.1+
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11659

A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this vulnerability …

Mitigation only
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11660

A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this issue…

Mitigation only
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11658

A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected is an unknown f…

Mitigation only
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11657

A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This impac…

Mitigation only
Fix from $2,300 2025-10-13
School Management System CRITICAL 9.8
CVE-2025-11656

A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknow…

Mitigation only
Fix from $2,300 2025-10-13
Furbo Mini Firmware MEDIUM 6.8
CVE-2025-11647

A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component GATT Service. This manipulatio…

Fix: after 074
Fix from $1,600 2025-10-12
Furbo Mini Firmware HIGH 8.1
CVE-2025-11646

A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the component GATT Service. The manipula…

Fix: after 074
Fix from $1,950 2025-10-12
Furbo Mini Firmware MEDIUM 6.4
CVE-2025-11641

A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This…

Fix: after 074
Fix from $1,600 2025-10-12
Unclassified HIGH 8.7
CVE-2025-62159

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability wa…

Mitigation only
Fix from $1,950 2025-10-10
Simple Car Rental System CRITICAL 9.9
CVE-2025-60306

code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sens…

Mitigation only
Fix from $2,300 2025-10-10
Online Student Clearance System HIGH 8.8
CVE-2025-60305

SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low …

No fix yet
Fix from $1,950 2025-10-10
Entra Id CRITICAL 9.6
CVE-2025-59218

Azure Entra ID Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
Unclassified HIGH 7.3
CVE-2025-45095

Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unqu…

Mitigation only
Fix from $1,950 2025-10-09