Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Boyuncms CRITICAL 9.8
CVE-2025-7100

A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /appl…

Fix: after 1.4.20
Fix from $2,300 2025-07-07
Blackvue Dr590x Firmware HIGH 8.8
CVE-2025-7076

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionalit…

Fix: after 2025-06-24
Fix from $1,950 2025-07-06
Blackvue Dr590x Firmware HIGH 8.8
CVE-2025-7075

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as critical. Affected by this vulnerability is an unknown fun…

Fix: after 2025-06-24
Fix from $1,950 2025-07-06
Unclassified MEDIUM 5.3
CVE-2025-6786

The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, 1.1.5. This is due to plugin …

Mitigation only
Fix from $1,600 2025-07-04
Scribunto HIGH 8.8
CVE-2025-53501

Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrain…

Patch available
Fix from $1,950 2025-07-03
Xinference MEDIUM 5.3
CVE-2025-45424

Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.

Fix: 1.4.0+
Fix from $1,600 2025-07-02
Unclassified CRITICAL 9.8
CVE-2025-52101

linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authenticat…

Mitigation only
Fix from $2,300 2025-07-01
Unclassified MEDIUM 6.5
CVE-2025-27153

Escalade GLPI plugin is a ticket escalation process helper for GLPI. Prior to version 2.9.11, there is an improper access control vulnerability. This…

Mitigation only
Fix from $1,600 2025-07-01
Unclassified HIGH 8.8
CVE-2025-45081

Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.

No fix yet
Fix from $1,950 2025-07-01
Unclassified MEDIUM 6.1
CVE-2025-45083

Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental pin feature via unspecified ve…

No fix yet
Fix from $1,600 2025-07-01
Rx 1500 Firmware MEDIUM 6.5
CVE-2025-50405

Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation functio…

Fix: after 2.2.17
Fix from $1,600 2025-07-01
Unclassified HIGH 8.2
CVE-2025-53003

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without s…

Patch available
Fix from $1,950 2025-07-01
Library System CRITICAL 9.8
CVE-2025-6900

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /a…

Mitigation only
Fix from $2,300 2025-06-30
Pc Manager HIGH 8.8
CVE-2025-46014

Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with d…

Fix: after 16.0.0.118
Fix from $1,950 2025-06-30
Simple Company Website HIGH 7.2
CVE-2025-6873

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown proce…

No fix yet
Fix from $1,950 2025-06-29
Simple Company Website HIGH 7.2
CVE-2025-6872

A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /c…

No fix yet
Fix from $1,950 2025-06-29
Simple Forum HIGH 8.8
CVE-2025-6848

A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of th…

No fix yet
Fix from $1,950 2025-06-29
Simple Photo Gallery CRITICAL 9.8
CVE-2025-6843

A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file …

Mitigation only
Fix from $2,300 2025-06-29
Library System CRITICAL 9.8
CVE-2025-6837

A vulnerability classified as critical was found in code-projects Library System 1.0. Affected by this vulnerability is an unknown functionality of t…

Mitigation only
Fix from $2,300 2025-06-29
Unclassified MEDIUM 6.3
CVE-2023-29113

The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process comm…

Mitigation only
Fix from $1,600 2025-06-28
Unclassified MEDIUM 6.7
CVE-2023-28907

There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to com…

Mitigation only
Fix from $1,600 2025-06-28
Dir 823 Pro Firmware MEDIUM 6.3
CVE-2025-45729

D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.

No fix yet
Fix from $1,600 2025-06-27
Unclassified CRITICAL 9.1
CVE-2025-49603

Northern.tech Mender Server before 3.7.11 and 4.x before 4.0.1 has Incorrect Access Control.

Mitigation only
Fix from $2,300 2025-06-26
Arc HIGH 8.3
CVE-2024-52928

Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permission…

Fix: 1.26.1+
Fix from $1,950 2025-06-26
Car Rental System HIGH 8.8
CVE-2025-6667

A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

No fix yet
Fix from $1,950 2025-06-25
Routeros HIGH 7.2
CVE-2025-6443

Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on …

Fix: 7.20+
Fix from $1,950 2025-06-25
Terminal Handler CRITICAL 9.8
CVE-2023-47031

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to escalate privileges via a crafted POST request to the grantRolesToUsers, grantRo…

Mitigation only
Fix from $2,300 2025-06-23
Terminal Handler HIGH 8.1
CVE-2023-47294

An issue in NCR Terminal Handler v1.5.1 allows low-level privileged authenticated attackers to arbitrarily deactivate, lock, and delete user accounts…

Mitigation only
Fix from $1,950 2025-06-23
Terminal Handler CRITICAL 9.8
CVE-2023-47297

A settings manipulation vulnerability in NCR Terminal Handler v1.5.1 allows attackers to execute arbitrary commands, including editing system securit…

Mitigation only
Fix from $2,300 2025-06-23
Ruoyi Ai CRITICAL 9.8
CVE-2025-6466

A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function speechToTextTranscriptionsV2/u…

Fix: 2.0.1+
Fix from $2,300 2025-06-22