Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2025-45613 Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload. Shiro Action after 0.6 Fix from $1,9502025-05-05 HIGH 7.5 CVE-2025-45614 Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information via a crafted payload. One No fix yet Fix from $1,9502025-05-05 CRITICAL 9.8 CVE-2025-45615 Incorrect access control in the /admin/ API of yaoqishan v0.0.1-SNAPSHOT allows attackers to gain access to Admin rights via a crafted request. Yaoqishan No fix yet Fix from $2,3002025-05-05 CRITICAL 9.8 CVE-2025-45616 Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request. Brcc after 1.2.0 Fix from $2,3002025-05-05 HIGH 7.5 CVE-2025-45617 Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted… Production Ssm No fix yet Fix from $1,9502025-05-05 HIGH 7.5 CVE-2025-45608 Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a craft… Xinguan after 0.0.1-snapshot Fix from $1,9502025-05-05 MEDIUM 6.3 CVE-2025-4051 Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific… Chrome 136.0.7103.59+ Fix from $1,6002025-05-05 HIGH 7.5 CVE-2025-45237 Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account i… Dbsyncer No fix yet Fix from $1,9502025-05-05 HIGH 7.5 CVE-2025-4270EPSS 13% A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/… A720r Firmware No fix yet Fix from $1,9502025-05-05 MEDIUM 5.3 CVE-2025-4271 A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerability is an unknown functional… A720r Firmware No fix yet Fix from $1,6002025-05-05 MEDIUM 5.3 CVE-2025-4269 A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/c… A720r Firmware No fix yet Fix from $1,6002025-05-05 CRITICAL 9.8 CVE-2025-4259 A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/n… Newbee Mall No fix yet Fix from $2,3002025-05-05 HIGH 8.8 CVE-2025-4258 A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu up to 4.2.0. Affected is the function Upload of the file \youk… Youkefu after 4.2.0 Fix from $1,9502025-05-05 CRITICAL 9.1 CVE-2024-48905 Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint. Replyone No fix yet Fix from $2,3002025-05-01 HIGH 7.1 CVE-2025-46635 An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces… Rx2 Pro Firmware No fix yet Fix from $1,9502025-05-01 HIGH 7.3 CVE-2025-46628 Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain… Rx2 Pro Firmware No fix yet Fix from $1,9502025-05-01 MEDIUM 6.5 CVE-2025-46629 Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthor… Rx2 Pro Firmware No fix yet Fix from $1,6002025-05-01 CRITICAL 9.8 CVE-2025-46566 DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC lin… Dataease 2.10.9+ Fix from $2,3002025-05-01 MEDIUM 6.3 CVE-2025-24887 OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed,… Opencti after 6.4.10 Fix from $1,6002025-04-30 CRITICAL 9.8 CVE-2025-46331 OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v… Helm Charts 0.2.29 / 1.8.11+ Fix from $2,3002025-04-30 HIGH 7.6 CVE-2025-46619 A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized acce… Couchbase Server 7.2.7 / 7.6.4+ Fix from $1,9502025-04-30 HIGH 8.8 CVE-2025-27134 Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. Prior to version … Joplin 3.3.3+ Fix from $1,9502025-04-30 HIGH 7.5 CVE-2025-4119 A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the compon… Mall Mitigation only Fix from $1,9502025-04-30 CRITICAL 9.1 CVE-2025-4118 A vulnerability classified as critical has been found in Weitong Mall 1.0.0. This affects an unknown part of the file /historyList of the component P… Mall Mitigation only Fix from $2,3002025-04-30 MEDIUM 6.3 CVE-2025-46552 KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some comm… Patch available Fix from $1,6002025-04-29 CRITICAL 9.8 CVE-2025-25962 An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function Mitigation only Fix from $2,3002025-04-29 HIGH 7.5 CVE-2025-4065 A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerability affects unknown code of … Online Traveling System Mitigation only Fix from $1,9502025-04-29 CRITICAL 9.8 CVE-2025-4066 A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of … Online Traveling System Mitigation only Fix from $2,3002025-04-29 MEDIUM 5.3 CVE-2025-4067 A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unknown function of the file /admi… Online Traveling System Mitigation only Fix from $1,6002025-04-29 MEDIUM 5.3 CVE-2025-4064 A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects an unknown part of the file … Online Traveling System Mitigation only Fix from $1,6002025-04-29