Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Chancms CRITICAL 9.8
CVE-2025-8226

A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sy…

Fix: 3.1.3+
Fix from $2,300 2025-07-27
Voting System MEDIUM 6.3
CVE-2025-8174

A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

No fix yet
Fix from $1,600 2025-07-26
Document Management System MEDIUM 6.3
CVE-2025-8171

A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This issue affects some unknown pr…

Mitigation only
Fix from $1,600 2025-07-25
Unclassified MEDIUM 6.3
CVE-2025-8128

A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de48f7fbe98. This issue affects …

Mitigation only
Fix from $1,600 2025-07-25
Devolutions Server HIGH 7.7
CVE-2025-6741

Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure m…

Fix: 2025.2.5.0+
Fix from $1,950 2025-07-22
Jpacookieshop HIGH 8.8
CVE-2025-7939

A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of t…

No fix yet
Fix from $1,950 2025-07-21
E2500 Firmware CRITICAL 9.8
CVE-2025-44654

In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to syst…

Mitigation only
Fix from $2,300 2025-07-21
Church Donation System HIGH 7.3
CVE-2025-7931

A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown function…

No fix yet
Fix from $1,950 2025-07-21
Ruckus Unleashed MEDIUM 5.3
CVE-2025-46118

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, w…

Fix: 10.5.1.0.279 / 200.15.6.212.14+
Fix from $1,600 2025-07-21
Ruoyi MEDIUM 5.4
CVE-2025-7906

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi…

Fix: after 4.8.1
Fix from $1,600 2025-07-20
Identsoft HIGH 7.2
CVE-2025-7898

A vulnerability was found in Codecanyon iDentSoft 2.0. It has been classified as critical. This affects an unknown part of the file /clinica/profile/…

No fix yet
Fix from $1,950 2025-07-20
Moneyprinterturbo CRITICAL 9.8
CVE-2025-7895

A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of …

Fix: after 1.2.6
Fix from $2,300 2025-07-20
Metacrm HIGH 8.8
CVE-2025-7880

A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this issue is some unknown functionality o…

Fix: after 6.4.2
Fix from $1,950 2025-07-20
Metacrm CRITICAL 9.8
CVE-2025-7879

A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnerability is an unknown func…

Fix: after 6.4.2
Fix from $2,300 2025-07-20
Metacrm HIGH 8.8
CVE-2025-7878

A vulnerability, which was classified as critical, was found in Metasoft 美特软件 MetaCRM up to 6.4.2. Affected is an unknown function of the file /c…

Fix: after 6.4.2
Fix from $1,950 2025-07-20
Metacrm CRITICAL 9.8
CVE-2025-7877

A vulnerability, which was classified as critical, has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This issue affects some unknown processin…

Fix: after 6.4.2
Fix from $2,300 2025-07-20
Metacrm CRITICAL 9.1
CVE-2025-7874

A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue is some unknown function…

Fix: after 6.4.2
Fix from $2,300 2025-07-20
Jeesite MEDIUM 5.4
CVE-2025-7864

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main…

Fix: 5.12.1+
Fix from $1,600 2025-07-20
Unclassified MEDIUM 6.5
CVE-2025-52166

Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate privileges to Administrator …

Mitigation only
Fix from $1,600 2025-07-18
Unclassified MEDIUM 6.5
CVE-2025-52168

Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers…

Mitigation only
Fix from $1,600 2025-07-18
Splashin MEDIUM 6.5
CVE-2025-45157

Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.

No fix yet
Fix from $1,600 2025-07-18
Online Ordering System HIGH 8.8
CVE-2025-7755

A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of t…

No fix yet
Fix from $1,950 2025-07-17
Vm Virtualbox HIGH 8.2
CVE-2025-53028

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas…

Mitigation only
Fix from $1,950 2025-07-15
Universal Work Queue MEDIUM 6.1
CVE-2025-50107

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Request handling). Supported versions that are affec…

Fix: after 12.2.14
Fix from $1,600 2025-07-15
Hyperion Financial Reporting MEDIUM 5.4
CVE-2025-50108

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Workspace). The supported version that is affected …

Patch available
Fix from $1,600 2025-07-15
Universal Work Queue HIGH 8.1
CVE-2025-50105

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). Supported versions th…

Fix: after 12.2.14
Fix from $1,950 2025-07-15
Database Server MEDIUM 5.3
CVE-2025-50070

Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 23.4-23.8. Difficult to exploit vulnerabilit…

Fix: after 23.8
Fix from $1,600 2025-07-15
Applications Framework MEDIUM 6.4
CVE-2025-50071

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affect…

Fix: after 12.2.14
Fix from $1,600 2025-07-15
Jre HIGH 8.6
CVE-2025-50059

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Su…

Mitigation only
Fix from $1,950 2025-07-15
Bi Publisher HIGH 8.1
CVE-2025-50060

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.6.0.0.0, 8.…

Patch available
Fix from $1,950 2025-07-15