Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Flagforge HIGH 8.2
CVE-2025-59932

Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE …

Fix: 2.3.1+
Fix from $1,950 2025-09-27
Vvveb HIGH 7.5
CVE-2025-11028

A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image Handler. Performing manipulati…

Fix: after 1.0.7.2
Fix from $1,950 2025-09-26
Vvveb HIGH 7.5
CVE-2025-11026

A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality of the component Configurati…

Fix: after 1.0.7.2
Fix from $1,950 2025-09-26
Stormshield Network Security HIGH 7.5
CVE-2025-48707

An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared amo…

Fix: 5.0.1+
Fix from $1,950 2025-09-25
Unclassified MEDIUM 5.3
CVE-2025-10952

A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream…

Mitigation only
Fix from $1,600 2025-09-25
Unclassified HIGH 8.7
CVE-2025-10957

This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could explo…

Mitigation only
Fix from $1,950 2025-09-25
Unclassified HIGH 7.5
CVE-2025-56241EPSS 6%

Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a …

No fix yet
Fix from $1,950 2025-09-24
Horilla HIGH 7.5
CVE-2025-48869

Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by…

No fix yet
Fix from $1,950 2025-09-24
Unclassified MEDIUM 5.3
CVE-2025-20316

A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow …

Mitigation only
Fix from $1,600 2025-09-24
Unclassified MEDIUM 5.8
CVE-2025-20339

A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote att…

Mitigation only
Fix from $1,600 2025-09-24
Librechat MEDIUM 5.3
CVE-2025-7106

danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/…

Fix: 0.7.9+
Fix from $1,600 2025-09-23
Unclassified CRITICAL 9.6
CVE-2025-59434

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated …

Mitigation only
Fix from $2,300 2025-09-22
Ip 4c Firmware MEDIUM 6.8
CVE-2025-57438

The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only afte…

No fix yet
Fix from $1,600 2025-09-22
Unclassified HIGH 7.7
CVE-2025-5962

A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to access and manipulate the chat h…

Mitigation only
Fix from $1,950 2025-09-22
Unclassified MEDIUM 6.3
CVE-2025-10763

A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by this issue is some unknown func…

Mitigation only
Fix from $1,600 2025-09-21
Unclassified MEDIUM 6.3
CVE-2025-10755

A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component Content-Type Handler. The ma…

Mitigation only
Fix from $1,600 2025-09-20
Unclassified MEDIUM 6.3
CVE-2025-10741

A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown function of the component Profile …

Mitigation only
Fix from $1,600 2025-09-20
Unclassified MEDIUM 6.3
CVE-2025-10669

A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component Playlist Upload Handler. Per…

Mitigation only
Fix from $1,600 2025-09-18
Triton Inference Server HIGH 7.5
CVE-2025-23329

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corruption by identifying and acce…

Fix: 25.08+
Fix from $1,950 2025-09-17
E Commerce Website HIGH 8.8
CVE-2025-10616

A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipul…

No fix yet
Fix from $1,950 2025-09-17
E Commerce Website HIGH 8.8
CVE-2025-10615

A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipula…

No fix yet
Fix from $1,950 2025-09-17
I Educar HIGH 8.8
CVE-2025-10608

A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Perform…

Fix: after 2.10.0
Fix from $1,950 2025-09-17
I Educar MEDIUM 6.5
CVE-2025-10607

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi…

Fix: after 2.10.0
Fix from $1,600 2025-09-17
Online Exam Form Submission CRITICAL 9.8
CVE-2025-10600

A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulatio…

Mitigation only
Fix from $2,300 2025-09-17
Unclassified HIGH 7.5
CVE-2025-37125

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass…

Mitigation only
Fix from $1,950 2025-09-16
Unclassified CRITICAL 9.1
CVE-2025-54391

A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypas…

Mitigation only
Fix from $2,300 2025-09-16
Mcp Database Server HIGH 8.1
CVE-2025-59333

The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement ade…

Fix: after 1.1.0
Fix from $1,950 2025-09-16
macOS MEDIUM 5.5
CVE-2025-43369

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26. An app may be able to access protected user data.

Fix: 26.0+
Fix from $1,600 2025-09-15
Xcode HIGH 8.2
CVE-2025-43371

This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.

Fix: 26.0+
Fix from $1,950 2025-09-15
macOS MEDIUM 5.5
CVE-2025-43337

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26. An app may be able t…

Fix: 26.0+
Fix from $1,600 2025-09-15