Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified CRITICAL 9.8
CVE-2022-43110

Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspe…

Mitigation only
Fix from $2,300 2025-08-22
My Site CRITICAL 9.8
CVE-2024-53496

Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.

Mitigation only
Fix from $2,300 2025-08-22
Unclassified MEDIUM 5.3
CVE-2025-55626

An Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_25031222…

Mitigation only
Fix from $1,600 2025-08-22
Smart 2k\+ Plug In Wi Fi Video Doorbell With Chime Firmware HIGH 7.3
CVE-2025-55630

A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662…

No fix yet
Fix from $1,950 2025-08-22
Unclassified HIGH 7.5
CVE-2024-53494

Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication.

Mitigation only
Fix from $1,950 2025-08-22
Unopim HIGH 8.1
CVE-2025-55741

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the…

Fix: 0.3.1+
Fix from $1,950 2025-08-22
Purview Data Governance CRITICAL 9.8
CVE-2025-53763

Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-08-21
N Central HIGH 8.3
CVE-2025-7051

On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This …

Fix: 2025.2+
Fix from $1,950 2025-08-21
Unclassified CRITICAL 9.1
CVE-2024-45438

An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within …

Mitigation only
Fix from $2,300 2025-08-21
Jsherp MEDIUM 5.3
CVE-2025-55371

Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the informatio…

No fix yet
Fix from $1,600 2025-08-21
Jsherp MEDIUM 5.3
CVE-2025-55366

Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords…

No fix yet
Fix from $1,600 2025-08-21
Jsherp MEDIUM 5.3
CVE-2025-55367

Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the …

No fix yet
Fix from $1,600 2025-08-21
Jsherp HIGH 8.8
CVE-2025-55368

Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supp…

No fix yet
Fix from $1,950 2025-08-21
Emlog CRITICAL 9.8
CVE-2025-9296

A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_a…

Fix: after 2.5.18
Fix from $2,300 2025-08-21
Unclassified HIGH 8.1
CVE-2025-27215

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported c…

Mitigation only
Fix from $1,950 2025-08-21
Unclassified CRITICAL 9.8
CVE-2024-57155

Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token.

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 9.8
CVE-2024-57154

Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.

Mitigation only
Fix from $2,300 2025-08-20
My Site HIGH 7.5
CVE-2024-57152

Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the c…

No fix yet
Fix from $1,950 2025-08-20
My Site HIGH 7.5
CVE-2024-53495

Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.

No fix yet
Fix from $1,950 2025-08-20
Itranswarp HIGH 8.6
CVE-2025-28041

Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication.

Fix: after 2.19
Fix from $1,950 2025-08-20
Unclassified CRITICAL 9.8
CVE-2024-57157

Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.

Mitigation only
Fix from $2,300 2025-08-20
Online Tour \& Travel Management System HIGH 8.8
CVE-2025-9153

A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin…

No fix yet
Fix from $1,950 2025-08-19
Unclassified MEDIUM 5.3
CVE-2025-50434

A security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is related to incorrect access …

No fix yet
Fix from $1,600 2025-08-19
Ezged3 MEDIUM 5.3
CVE-2025-51539

EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficient input validation in a scri…

Fix: 3.5.72.27183+
Fix from $1,600 2025-08-19
Cookies And Content Security Policy MEDIUM 5.3
CVE-2025-51529

Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows rem…

Fix: after 2.29
Fix from $1,600 2025-08-19
Scada Lts MEDIUM 6.5
CVE-2025-9139

A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plain…

No fix yet
Fix from $1,600 2025-08-19
Unclassified HIGH 8.5
CVE-2025-32992

Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.

Mitigation only
Fix from $1,950 2025-08-18
Unclassified HIGH 7.7
CVE-2025-4962

An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Lunary API, affecting versions up…

Patch available
Fix from $1,950 2025-08-18
Unclassified MEDIUM 6.3
CVE-2025-9099

A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/…

Mitigation only
Fix from $1,600 2025-08-18
Buttercup MEDIUM 6.5
CVE-2017-20199

A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an unknown functionality of the co…

Fix: 1.0.1+
Fix from $1,600 2025-08-16