Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Voting System CRITICAL 9.8
CVE-2025-11508

A security vulnerability has been detected in code-projects Voting System 1.0. This affects an unknown function of the file /admin/voters_add.php. Su…

Mitigation only
Fix from $2,300 2025-10-08
Hotel And Lodge Management System HIGH 7.2
CVE-2025-11470

A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted element is an unknown function…

No fix yet
Fix from $1,950 2025-10-08
Opnform HIGH 8.8
CVE-2025-11436

A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulati…

Fix: after 1.9.3
Fix from $1,950 2025-10-08
Advanced Library Management System HIGH 8.8
CVE-2025-11426

A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionali…

No fix yet
Fix from $1,950 2025-10-08
Advanced Online Voting System HIGH 8.8
CVE-2025-11417

A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unknown code of the file /admin/…

No fix yet
Fix from $1,950 2025-10-08
Hotel And Lodge Management System HIGH 8.8
CVE-2025-11398

A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The impacted element is an unknown function of the file /prof…

No fix yet
Fix from $1,950 2025-10-07
Online Hotel Reservation System CRITICAL 9.8
CVE-2025-11354

A flaw has been found in code-projects Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/addslideexec.php. Exec…

Mitigation only
Fix from $2,300 2025-10-07
Online Hotel Reservation System HIGH 8.8
CVE-2025-11353

A vulnerability was detected in code-projects Online Hotel Reservation System 1.0. This impacts an unknown function of the file /admin/addgalleryexec…

No fix yet
Fix from $1,950 2025-10-07
Online Hotel Reservation System HIGH 8.8
CVE-2025-11351

A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/e…

No fix yet
Fix from $1,950 2025-10-07
Online Hotel Reservation System HIGH 8.8
CVE-2025-11352

A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown function of the file /admin/…

No fix yet
Fix from $1,950 2025-10-07
Crud Operation System CRITICAL 9.8
CVE-2025-11347

A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file a…

Fix: after 3.3
Fix from $2,300 2025-10-07
Flagforge CRITICAL 9.1
CVE-2025-61777

Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/a…

Fix: 2.3.2+
Fix from $2,300 2025-10-06
Unclassified CRITICAL 9.1
CVE-2025-57247

The BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa7a) contains incorrect access…

Mitigation only
Fix from $2,300 2025-10-06
Unclassified MEDIUM 6.3
CVE-2025-11320

A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. Impacted is the function uploadFile of the file src/main…

Mitigation only
Fix from $1,600 2025-10-06
Data Leakage Prevention System CRITICAL 9.8
CVE-2025-11318

A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability af…

Mitigation only
Fix from $2,300 2025-10-06
Learning MEDIUM 5.0
CVE-2025-11281

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished C…

No fix yet
Fix from $1,600 2025-10-05
Phpmyfaq CRITICAL 9.8
CVE-2025-59943

phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user re…

Patch available
Fix from $2,300 2025-10-03
Termix CRITICAL 9.1
CVE-2025-59951

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix v…

Fix: after 1.6.0
Fix from $2,300 2025-10-01
Splunk MEDIUM 6.5
CVE-2025-20366

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a…

Fix: 9.2.8 / 9.2.2406.122+
Fix from $1,600 2025-10-01
Transformation Extender Advanced MEDIUM 6.2
CVE-2023-50300

IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.

Mitigation only
Fix from $1,600 2025-10-01
Unclassified HIGH 8.4
CVE-2025-10847

DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A r…

Mitigation only
Fix from $1,950 2025-10-01
Formcms MEDIUM 6.5
CVE-2025-55797

An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access…

Mitigation only
Fix from $1,600 2025-09-30
Freshrss CRITICAL 9.8
CVE-2025-54875

FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker can create a new admin user w…

Fix: 1.27.0+
Fix from $2,300 2025-09-29
Unclassified CRITICAL 9.8
CVE-2025-57266

An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain se…

Mitigation only
Fix from $2,300 2025-09-29
Freshrss HIGH 7.5
CVE-2025-54591

FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of default admin users, due to la…

Fix: 1.27.0+
Fix from $1,950 2025-09-29
Unclassified MEDIUM 6.0
CVE-2025-57197

In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A loc…

Mitigation only
Fix from $1,600 2025-09-29
Unclassified MEDIUM 6.5
CVE-2025-57428

Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell ex…

Mitigation only
Fix from $1,600 2025-09-29
Yifang HIGH 7.2
CVE-2025-11136

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the comp…

Fix: after 2.0.2
Fix from $1,950 2025-09-29
Online Tours And Travels HIGH 7.2
CVE-2025-11103

A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality …

No fix yet
Fix from $1,950 2025-09-28
Open Source Job Portal HIGH 8.8
CVE-2025-11078

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /ad…

No fix yet
Fix from $1,950 2025-09-27