Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Online Recruitment Management System HIGH 8.8
CVE-2025-6422

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown …

No fix yet
Fix from $1,950 2025-06-21
Flir Ax8 Firmware CRITICAL 9.8
CVE-2025-6266

A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Per…

Fix: 1.49.16+
Fix from $2,300 2025-06-19
Traffic Server HIGH 7.5
CVE-2025-31698

ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.…

Fix: 9.2.11 / 10.0.6+
Fix from $1,950 2025-06-19
Unclassified CRITICAL 9.8
CVE-2024-45208

The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP …

Mitigation only
Fix from $2,300 2025-06-19
Cryptpad CRITICAL 9.1
CVE-2025-49591

CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, d…

Fix: 2025.3.0+
Fix from $2,300 2025-06-18
Worry Free Business Security HIGH 7.8
CVE-2025-49154

An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwri…

Fix: 6.7.3954 / 14.0.0.14002+
Fix from $1,950 2025-06-17
Simple Food Ordering System CRITICAL 9.8
CVE-2025-6161

A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of th…

Mitigation only
Fix from $2,300 2025-06-17
Idrac Tools HIGH 7.8
CVE-2025-27689

Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access coul…

Fix: 11.3.0.0+
Fix from $1,950 2025-06-12
Experience Manager MEDIUM 5.4
CVE-2025-46889

Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalati…

Fix: 6.5.23.0 / 2025.5.0+
Fix from $1,600 2025-06-10
Windows Software Development Kit HIGH 7.8
CVE-2025-47962

Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.4188+
Fix from $1,950 2025-06-10
Windows 10 1507 HIGH 8.8
CVE-2025-33073 KEVEPSS 80%

Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Windows 10 1507 HIGH 7.5
CVE-2025-33056

Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Windows 10 1507 MEDIUM 5.5
CVE-2025-32722

Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,600 2025-06-10
Windows 10 1507 HIGH 7.8
CVE-2025-32714

Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Erxes CRITICAL 9.8
CVE-2024-57190

Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any use…

Fix: 1.6.1+
Fix from $2,300 2025-06-10
Commerce HIGH 8.1
CVE-2025-43586

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that co…

Mitigation only
Fix from $1,950 2025-06-10
Commerce MEDIUM 5.3
CVE-2025-27206

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that co…

Mitigation only
Fix from $1,600 2025-06-10
Commerce B2b MEDIUM 6.5
CVE-2025-27207

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that co…

Mitigation only
Fix from $1,600 2025-06-10
Unclassified MEDIUM 6.3
CVE-2025-5873

A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmwa…

Mitigation only
Fix from $1,600 2025-06-09
Client Database Management System HIGH 7.3
CVE-2025-5840

A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of…

No fix yet
Fix from $1,950 2025-06-07
Open Source Clinic Management System HIGH 8.8
CVE-2025-5728

A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code …

No fix yet
Fix from $1,950 2025-06-06
Devolutions Server MEDIUM 6.8
CVE-2025-5382

Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or …

Fix: 2025.1.9.0+
Fix from $1,600 2025-06-05
Devolutions Server MEDIUM 5.0
CVE-2025-3768

Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor …

Fix: after 2025.1.10.0
Fix from $1,600 2025-06-05
Devolutions Server MEDIUM 5.0
CVE-2025-0691

Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permi…

Fix: after 2025.1.10.0
Fix from $1,600 2025-06-05
Student Result Management System MEDIUM 6.5
CVE-2025-5649

A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the fil…

No fix yet
Fix from $1,600 2025-06-05
Identity Services Engine HIGH 7.2
CVE-2025-20130

A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, r…

Fix: 3.1.0+
Fix from $1,950 2025-06-04
Dataease HIGH 8.8
CVE-2025-48999EPSS 8%

DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10.…

Fix: 2.10.10+
Fix from $1,950 2025-06-03
Aqt1000 Firmware HIGH 7.8
CVE-2024-53010

Memory corruption may occur while attaching VM when the HLOS retains access to VM.

Mitigation only
Fix from $1,950 2025-06-03
Unclassified MEDIUM 5.3
CVE-2025-5436

A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic. This issue affects some unknown processing of the file…

Mitigation only
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5429

A vulnerability classified as critical was found in juzaweb CMS up to 3.4.2. This vulnerability affects unknown code of the file /admin-cp/plugin/ins…

Fix: after 3.4.2
Fix from $1,600 2025-06-02