Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Cms MEDIUM 6.3
CVE-2025-5427

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5428

A vulnerability classified as critical has been found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/log-viewer of th…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5424

A vulnerability was found in juzaweb CMS up to 3.4.2 and classified as critical. This issue affects some unknown processing of the file /admin-cp/med…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5425

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as critical. Affected is an unknown function of the file /admin-cp/theme…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5426

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5423

A vulnerability has been found in juzaweb CMS up to 3.4.2 and classified as critical. This vulnerability affects unknown code of the file /admin-cp/s…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5421

A vulnerability, which was classified as critical, has been found in juzaweb CMS up to 3.4.2. Affected by this issue is some unknown functionality of…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Mist CRITICAL 9.8
CVE-2025-5409

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the fi…

Fix: 4.7.2+
Fix from $2,300 2025-06-01
Blogbook HIGH 8.8
CVE-2025-5406

A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an…

Fix: after 2021-11-22
Fix from $1,950 2025-06-01
Jeewms CRITICAL 9.8
CVE-2025-5389

A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many…

Fix: after 2025-05-04
Fix from $2,300 2025-05-31
Jeewms CRITICAL 9.8
CVE-2025-5390

A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemControll…

Fix: after 2025-05-04
Fix from $2,300 2025-05-31
Jeewms CRITICAL 9.8
CVE-2025-5387

A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.d…

Fix: after 2025-05-04
Fix from $2,300 2025-05-31
Devolutions Server HIGH 8.8
CVE-2025-4433

Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Manage…

Fix: 2025.1.9.0+
Fix from $1,950 2025-05-30
Wifi Lock Controller V1 Rf Firmware CRITICAL 9.1
CVE-2025-44619

Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without…

Mitigation only
Fix from $2,300 2025-05-30
Unclassified MEDIUM 6.5
CVE-2024-57336

Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to v8.0.3.79 allows unauthorized attackers to obtain Adm…

Mitigation only
Fix from $1,600 2025-05-28
W18e Firmware CRITICAL 9.8
CVE-2025-45343

An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the gof…

No fix yet
Fix from $2,300 2025-05-28
Commons Beanutils HIGH 8.8
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop att…

Fix: 1.11.0+
Fix from $1,950 2025-05-28
Client Database Management System HIGH 7.3
CVE-2025-5299

A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unkno…

No fix yet
Fix from $1,950 2025-05-28
Vacation Rental Management Platform HIGH 7.5
CVE-2025-5184

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been classified as problematic. Affected is a…

Fix: 1.0.2+
Fix from $1,950 2025-05-26
Queue Ticket Kiosk CRITICAL 9.8
CVE-2025-5178

A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected is an unknown function of the …

Fix: after 2025-05-17
Fix from $2,300 2025-05-26
Mta Maita Training System CRITICAL 9.8
CVE-2025-5171

A vulnerability, which was classified as critical, has been found in llisoft MTA Maita Training System 4.5. This issue affects the function this.file…

Mitigation only
Fix from $2,300 2025-05-26
Warehouse Management System MEDIUM 5.3
CVE-2025-5163

A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part…

No fix yet
Fix from $1,600 2025-05-26
Seccenter Smp 1114p02 CRITICAL 9.8
CVE-2025-5162

A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this issue is some unknow…

Fix: after 20250513
Fix from $2,300 2025-05-26
Tmall Demo HIGH 7.2
CVE-2025-5131

A vulnerability was found in Tmall Demo up to 20250505. It has been declared as critical. This vulnerability affects the function uploadCategoryImage…

Fix: after 2025-05-05
Fix from $1,950 2025-05-24
Tmall Demo HIGH 7.2
CVE-2025-5130

A vulnerability was found in Tmall Demo up to 20250505. It has been classified as critical. This affects the function uploadProductImage of the file …

Fix: after 2025-05-05
Fix from $1,950 2025-05-24
Nessus Network Monitor HIGH 7.8
CVE-2025-24917

In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local direct…

Fix: 6.5.1+
Fix from $1,950 2025-05-23
Nessus Network Monitor HIGH 7.8
CVE-2025-24916

When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce …

Fix: 6.5.1+
Fix from $1,950 2025-05-23
Unclassified MEDIUM 5.5
CVE-2025-3580

An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator a…

Mitigation only
Fix from $1,600 2025-05-23
Shopxo CRITICAL 9.8
CVE-2025-5108

A vulnerability was found in zongzhige ShopXO 6.5.0. It has been rated as critical. This issue affects the function Upload of the file app/admin/cont…

Mitigation only
Fix from $2,300 2025-05-23
Online Shopping Portal HIGH 7.2
CVE-2025-5059

A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. This affects an unknown part of the file /admin/edit-s…

No fix yet
Fix from $1,950 2025-05-21