Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2025-31258 This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of its sandbox. macOS 15.5+ Fix from $1,6002025-05-12 MEDIUM 5.5 CVE-2025-31260 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive use… macOS 15.5+ Fix from $1,6002025-05-12 HIGH 7.5 CVE-2025-31247 A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An … macOS 13.7.6 / 14.7.6+ Fix from $1,9502025-05-12 HIGH 7.1 CVE-2025-31232 A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A sandboxed a… macOS 13.7.6 / 14.7.6+ Fix from $1,9502025-05-12 MEDIUM 5.5 CVE-2025-31212 This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS … Ipados 2.5 / 11.5+ Fix from $1,6002025-05-12 MEDIUM 6.3 CVE-2025-31195 The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox. macOS 15.4+ Fix from $1,6002025-05-12 CRITICAL 9.1 CVE-2025-30436 This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able … Ipados 18.4+ Fix from $2,3002025-05-12 CRITICAL 9.8 CVE-2025-4538 A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipula… Kkfileview Mitigation only Fix from $2,3002025-05-11 MEDIUM 5.3 CVE-2025-4536 A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 1.0 and classified as critical. Affected by th… Group Audio Visual Integrated Management No fix yet Fix from $1,6002025-05-11 MEDIUM 5.3 CVE-2025-4535 A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio-Visual Integrated Management Platform 4.0. Affected… Group Audio Visual Integrated Management No fix yet Fix from $1,6002025-05-11 MEDIUM 6.8 CVE-2025-28201 An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access. Rx1800 Firmware No fix yet Fix from $1,6002025-05-09 CRITICAL 9.8 CVE-2025-4468 A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This issue affects some unknown proce… Online Student Clearance System No fix yet Fix from $2,3002025-05-09 HIGH 7.5 CVE-2025-33072 Improper access control in Azure allows an unauthorized attacker to disclose information over a network. Msagsfeedback.azurewebsites.net Mitigation only Fix from $1,9502025-05-08 MEDIUM 6.5 CVE-2025-20190 A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to r… Ios Xe Mitigation only Fix from $1,6002025-05-07 HIGH 7.5 CVE-2025-29448 Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a den… Easy\!appointments Patch available Fix from $1,9502025-05-07 CRITICAL 9.4 CVE-2025-46816 goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without arguments makes it possible fo… Patch available Fix from $2,3002025-05-06 HIGH 7.8 CVE-2025-21469 Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call. Fastconnect 6700 Firmware Mitigation only Fix from $1,9502025-05-06 HIGH 7.8 CVE-2025-21470 Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter. Aqt1000 Firmware Mitigation only Fix from $1,9502025-05-06 HIGH 7.8 CVE-2024-49842 Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions. Aqt1000 Firmware No fix yet Fix from $1,9502025-05-06 MEDIUM 6.3 CVE-2025-4333 A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function… Mitigation only Fix from $1,6002025-05-06 HIGH 7.7 CVE-2025-46588 Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confident… Harmonyos No fix yet Fix from $1,9502025-05-06 HIGH 7.1 CVE-2025-46589 Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confident… Harmonyos No fix yet Fix from $1,9502025-05-06 MEDIUM 6.3 CVE-2025-4310 A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/… Content Management System No fix yet Fix from $1,6002025-05-06 MEDIUM 6.3 CVE-2025-4305 A vulnerability has been found in kefaming mayi up to 1.3.9 and classified as critical. This vulnerability affects the function Upload of the file ap… Mitigation only Fix from $1,6002025-05-06 CRITICAL 9.8 CVE-2025-4291 A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unr… Ideacms after 1.6 Fix from $2,3002025-05-05 MEDIUM 6.5 CVE-2025-45618 Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensi… Jeeweb Mybatis Springboot No fix yet Fix from $1,6002025-05-05 HIGH 7.5 CVE-2025-45609 Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a crafted payloa… Kob No fix yet Fix from $1,9502025-05-05 HIGH 7.5 CVE-2025-45610 Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sensitive information via a craf… Passjava after 3.0.0 Fix from $1,9502025-05-05 CRITICAL 9.8 CVE-2025-45611 Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request. Hope Boot No fix yet Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-45612 Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index. Xmall after 1.1 Fix from $2,3002025-05-05