Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Cpuz.sys MEDIUM 6.5
CVE-2025-51060

An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as I…

No fix yet
Fix from $1,600 2025-08-05
Unclassified MEDIUM 6.5
CVE-2025-43980

An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN. They enable the SSH service by default with the credentials of root/admin. Th…

Mitigation only
Fix from $1,600 2025-08-05
Electron Capture HIGH 7.8
CVE-2025-54871

Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unpriv…

Fix: 2.20.0+
Fix from $1,950 2025-08-05
Xboot CRITICAL 9.8
CVE-2025-8526

A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file x…

Fix: after 3.3.4
Fix from $2,300 2025-08-04
Xboot MEDIUM 5.3
CVE-2025-8525

A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring Bo…

Fix: after 3.3.4
Fix from $1,600 2025-08-04
Kitchen Treasure CRITICAL 9.8
CVE-2025-8504

A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userreg…

Mitigation only
Fix from $2,300 2025-08-03
Unclassified HIGH 7.3
CVE-2025-23277

NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds …

Mitigation only
Fix from $1,950 2025-08-02
Unclassified CRITICAL 9.8
CVE-2025-50870

Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The myds GET parameter accepts an e…

Mitigation only
Fix from $2,300 2025-08-01
Rx 1500 Firmware CRITICAL 9.8
CVE-2025-26062

An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtai…

Mitigation only
Fix from $2,300 2025-07-31
Cs Cart HIGH 8.6
CVE-2025-50850

An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and ra…

Mitigation only
Fix from $1,950 2025-07-31
Unclassified HIGH 7.3
CVE-2025-29556

ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users with the Ad…

Mitigation only
Fix from $1,950 2025-07-31
Magnusbilling HIGH 8.0
CVE-2025-52289

A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted reque…

Patch available
Fix from $1,950 2025-07-31
Unclassified MEDIUM 5.4
CVE-2025-29557

ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privile…

Mitigation only
Fix from $1,600 2025-07-31
Online Hotel Reservation System HIGH 7.2
CVE-2025-8379

A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an unknown part of the file /adm…

No fix yet
Fix from $1,950 2025-07-31
Shio CRITICAL 9.8
CVE-2025-8344

A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-ap…

Fix: after 0.3.8
Fix from $2,300 2025-07-31
2mp Full Hd Smart Wi Fi Cctv Home Security Camera Firmware HIGH 7.8
CVE-2025-50777

The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability tha…

Mitigation only
Fix from $1,950 2025-07-30
Glpi MEDIUM 6.5
CVE-2025-53111

GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized acc…

Fix: 10.0.19+
Fix from $1,600 2025-07-30
macOS HIGH 8.8
CVE-2025-43270

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.…

Fix: 13.7.7 / 14.7.7+
Fix from $1,950 2025-07-30
macOS MEDIUM 5.5
CVE-2025-43241

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.…

Fix: 13.7.7 / 14.7.7+
Fix from $1,600 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43232

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.…

Fix: 13.7.7 / 14.7.7+
Fix from $2,300 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43233

This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A m…

Fix: 13.7.7 / 14.7.7+
Fix from $2,300 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43192

A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. Account-driven User…

Fix: 14.7.7 / 15.6+
Fix from $2,300 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43194

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be abl…

Fix: 13.7.7 / 14.7.7+
Fix from $2,300 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43198

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to acces…

Fix: 14.7.7 / 15.6+
Fix from $2,300 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43184

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.7, macOS Ventu…

Fix: 13.7.7 / 14.7.7+
Fix from $2,300 2025-07-30
Nanomq HIGH 8.8
CVE-2024-42655

An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wil…

Patch available
Fix from $1,950 2025-07-29
Pacs Server CRITICAL 9.8
CVE-2025-27724

A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file…

Mitigation only
Fix from $2,300 2025-07-28
Fx2 Firmware CRITICAL 9.8
CVE-2025-30133

An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD…

Mitigation only
Fix from $2,300 2025-07-28
Online Ordering System CRITICAL 9.8
CVE-2025-8256

A vulnerability classified as critical has been found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin…

Mitigation only
Fix from $2,300 2025-07-28
Exam Form Submission CRITICAL 9.8
CVE-2025-8255

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the…

Mitigation only
Fix from $2,300 2025-07-28