Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Unclassified MEDIUM 6.5
CVE-2025-50861

The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without auth…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 5.3
CVE-2025-20219

A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive Security Appliance (ASA) Soft…

Mitigation only
Fix from $1,600 2025-08-14
Litemall HIGH 8.8
CVE-2025-8965

A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/…

Fix: after 1.8.0
Fix from $1,950 2025-08-14
Unclassified MEDIUM 5.3
CVE-2025-48861

A vulnerability in the Task API endpoint of the ctrlX OS setup mechanism allowed a remote, unauthenticated attacker to access and extract internal ap…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified HIGH 8.0
CVE-2025-48860

A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access t…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.1
CVE-2025-55196

External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15.0 to before 0.19.2, a vulner…

Patch available
Fix from $1,950 2025-08-13
Unclassified MEDIUM 6.8
CVE-2025-8762

A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The man…

Mitigation only
Fix from $1,600 2025-08-13
Azure File Sync HIGH 7.8
CVE-2025-53729

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

Fix: 18.3.0.0 / 19.2.0.0+
Fix from $1,950 2025-08-12
Ecesv6 Series Azure Vm Firmware MEDIUM 5.5
CVE-2025-49707

Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.

No fix yet
Fix from $1,600 2025-08-12
Sql Server 2016 HIGH 8.8
CVE-2025-24999

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Fix: 13.0.6465.1 / 13.0.7060.1+
Fix from $1,950 2025-08-12
Unclassified MEDIUM 5.8
CVE-2025-24840

Improper access control for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated …

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.5
CVE-2025-24323

Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before version MR4_1.0b1 may allow a…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.7
CVE-2025-20099

Improper access control for some Intel(R) Rapid Storage Technology installation software may allow an authenticated user to potentially enable escala…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified HIGH 8.5
CVE-2025-55012

Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by …

Mitigation only
Fix from $1,950 2025-08-11
Eblog Site HIGH 8.8
CVE-2025-8859

A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/…

No fix yet
Fix from $1,950 2025-08-11
Microservices Platform MEDIUM 6.1
CVE-2025-8841

A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-b…

Fix: after 6.0.0
Fix from $1,600 2025-08-11
Samarium MEDIUM 6.1
CVE-2025-8798

A vulnerability was found in oitcode samarium up to 0.9.6. It has been classified as critical. Affected is an unknown function of the file /dashboard…

Fix: after 0.9.6
Fix from $1,600 2025-08-10
Litmus CRITICAL 9.9
CVE-2025-8795

A vulnerability, which was classified as critical, was found in LitmusChaos Litmus up to 3.19.0. This affects an unknown part of the file /auth/login…

Fix: after 3.19.0
Fix from $2,300 2025-08-10
Electronic Signature CRITICAL 9.8
CVE-2025-8775

A vulnerability was found in Qiyuesuo Eelectronic Signature Platform up to 4.34 and classified as critical. Affected by this issue is the function ex…

Fix: after 4.34
Fix from $2,300 2025-08-09
Litemall MEDIUM 5.4
CVE-2025-8764

A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upl…

Fix: after 1.8.0
Fix from $1,600 2025-08-09
Unclassified MEDIUM 5.3
CVE-2025-8738

A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code o…

Mitigation only
Fix from $1,600 2025-08-08
Unclassified MEDIUM 6.5
CVE-2024-42048

OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write…

Mitigation only
Fix from $1,600 2025-08-07
Suitecrm MEDIUM 5.3
CVE-2025-54786

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken au…

Mitigation only
Fix from $1,600 2025-08-07
Vedo Suite MEDIUM 6.5
CVE-2025-51054

Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior …

No fix yet
Fix from $1,600 2025-08-06
Exonaut MEDIUM 5.3
CVE-2024-55402

4C Strategies Exonaut before v22.4 was discovered to contain an access control issue.

Fix: 21.6.2.1-1 / 22.4+
Fix from $1,600 2025-08-06
Unclassified CRITICAL 9.8
CVE-2025-30127

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video r…

Mitigation only
Fix from $2,300 2025-08-06
Sage Dpw HIGH 7.5
CVE-2025-51532

Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted requ…

Fix: 2025_06_000+
Fix from $1,950 2025-08-06
Unclassified MEDIUM 6.5
CVE-2025-46391

CWE-284: Improper Access Control

No fix yet
Fix from $1,600 2025-08-06
315 5g Iot Modem Firmware HIGH 7.8
CVE-2025-27062

Memory corruption while handling client exceptions, allowing unauthorized channel access.

No fix yet
Fix from $1,950 2025-08-06
Unclassified MEDIUM 6.5
CVE-2025-51627

Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privil…

No fix yet
Fix from $1,600 2025-08-05