Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Real Estate Management System CRITICAL 9.8
CVE-2025-9847

A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This ma…

Mitigation only
Fix from $2,300 2025-09-03
Parking Management System HIGH 7.5
CVE-2025-9843

A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This mani…

Mitigation only
Fix from $1,950 2025-09-03
Mobile Shop Management System HIGH 8.8
CVE-2025-9841

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewPro…

No fix yet
Fix from $1,950 2025-09-03
Parking Management System HIGH 7.5
CVE-2025-9842

A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. Th…

Mitigation only
Fix from $1,950 2025-09-03
Beakon MEDIUM 5.3
CVE-2025-55373

Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to escalate privileges and exec…

Fix: 5.4.3+
Fix from $1,600 2025-09-02
Events And Groups HIGH 7.5
CVE-2025-54599

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used, when a victi…

Fix: after 2025-07-22
Fix from $1,950 2025-09-02
Sim MEDIUM 6.1
CVE-2025-9800

A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue is the function Import of th…

Fix: after 0.3.40
Fix from $1,600 2025-09-01
Tianti MEDIUM 5.4
CVE-2025-9795

A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jef…

Fix: after 2.3
Fix from $1,600 2025-09-01
Remote Clinic CRITICAL 9.8
CVE-2025-9775

A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.php. The manipulation of the …

Fix: after 2.0
Fix from $2,300 2025-09-01
Remote Clinic CRITICAL 9.8
CVE-2025-9772

A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Performing manipulation of the argu…

Fix: after 2.0
Fix from $2,300 2025-09-01
Vynamic Security Suite HIGH 8.1
CVE-2024-46916

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesyst…

Fix: after 4.3.0sr06
Fix from $1,950 2025-08-29
Unclassified HIGH 8.6
CVE-2025-39247

There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permi…

Mitigation only
Fix from $1,950 2025-08-29
Ac10 Firmware MEDIUM 5.3
CVE-2025-57219

Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or …

Mitigation only
Fix from $1,600 2025-08-28
Ris 9160 Firmware MEDIUM 6.8
CVE-2025-25734

Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenti…

No fix yet
Fix from $1,600 2025-08-26
Human Resource Information System CRITICAL 9.8
CVE-2025-9475

A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unknown functionality of the file…

Mitigation only
Fix from $2,300 2025-08-26
Human Resource Information System CRITICAL 9.8
CVE-2025-9476

A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some unknown functionality of the f…

Mitigation only
Fix from $2,300 2025-08-26
Bbs HIGH 7.5
CVE-2025-9461

A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePacka…

Fix: after 6.8
Fix from $1,950 2025-08-26
Greencms CRITICAL 9.8
CVE-2025-9415

A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The man…

Fix: after 2.3.0603
Fix from $2,300 2025-08-25
Perfreeblog HIGH 7.5
CVE-2025-29421

PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.

No fix yet
Fix from $1,950 2025-08-25
Rebuild CRITICAL 9.8
CVE-2025-50900

An issue was discovered in getrebuild/rebuild 4.0.4. The affected source code class is com.rebuild.web.RebuildWebInterceptor, and the affected functi…

Fix: after 4.0.4
Fix from $2,300 2025-08-25
Unclassified MEDIUM 6.5
CVE-2025-44178

DASAN GPON ONU H660WM H660WMR210825 is susceptible to improper access control under its default settings. Attackers can exploit this vulnerability to…

Mitigation only
Fix from $1,600 2025-08-25
Dsl 7740c Firmware MEDIUM 5.3
CVE-2025-29520

Incorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows authenticated attackers with l…

No fix yet
Fix from $1,600 2025-08-25
Unclassified MEDIUM 6.5
CVE-2025-29524

Incorrect access control in the component /cgi-bin/system_diagnostic_main.asp of DASAN GPON ONU H660WM H660WMR210825 allows attackers to access sensi…

Mitigation only
Fix from $1,600 2025-08-25
Unclassified MEDIUM 6.5
CVE-2024-46412

Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a crafted GET request sent to /com…

Mitigation only
Fix from $1,600 2025-08-25
Dsl 7740c Firmware CRITICAL 9.8
CVE-2025-29514

Incorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to download the con…

Mitigation only
Fix from $2,300 2025-08-25
Dsl 7740c Firmware CRITICAL 9.8
CVE-2025-29515

Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modify arbitr…

Mitigation only
Fix from $2,300 2025-08-25
Lemon CRITICAL 9.8
CVE-2025-9406

A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the c…

Fix: after 1.13.0
Fix from $2,300 2025-08-25
Yifang HIGH 8.8
CVE-2025-9400

A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This ma…

Fix: after 2.0.5
Fix from $1,950 2025-08-25
Yifang HIGH 7.5
CVE-2025-9398

A security vulnerability has been detected in YiFang CMS up to 2.0.5. Affected by this vulnerability is the function exportInstallTable of the file a…

Fix: after 2.0.5
Fix from $1,950 2025-08-25
Vvveb CRITICAL 9.8
CVE-2025-9397

A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits/media.php. Executing manipul…

Fix: after 1.0.7.2
Fix from $2,300 2025-08-24