Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2025-4036 A vulnerability was found in 201206030 Novel 3.5.0 and classified as critical. This issue affects the function updateBookChapter of the file src/main… Novel No fix yet Fix from $2,3002025-04-28 HIGH 7.5 CVE-2025-32470 A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device. No fix yet Fix from $1,9502025-04-28 HIGH 7.5 CVE-2025-3978 A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file… Lecms No fix yet Fix from $1,9502025-04-27 MEDIUM 5.3 CVE-2025-3975 A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of… Ecommerce Website In Php No fix yet Fix from $1,6002025-04-27 CRITICAL 9.8 CVE-2025-3969 A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processi… News Publishing Site Dashboard No fix yet Fix from $2,3002025-04-27 MEDIUM 5.3 CVE-2025-3966 A vulnerability was found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this issue is some unknown functionality of the file… Paicoding No fix yet Fix from $1,6002025-04-27 HIGH 7.6 CVE-2025-43862 Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even thou… Dify 0.6.12+ Fix from $1,9502025-04-25 HIGH 7.3 CVE-2025-43947 Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, su… Klims after 1.6_dev Fix from $1,9502025-04-22 CRITICAL 9.1 CVE-2025-28104 Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input. Flaskblog No fix yet Fix from $2,3002025-04-21 MEDIUM 6.5 CVE-2025-28367 mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this v… Mojoportal 2.9.1.0+ Fix from $1,6002025-04-21 CRITICAL 9.8 CVE-2025-3830 A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUplo… Kuangsimplebbs No fix yet Fix from $2,3002025-04-20 CRITICAL 9.8 CVE-2025-3807 A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com… My Bbs No fix yet Fix from $2,3002025-04-19 HIGH 7.2 CVE-2025-3798 A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminContr… Wcms No fix yet Fix from $1,9502025-04-19 CRITICAL 9.1 CVE-2025-28233 Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1… Mitigation only Fix from $2,3002025-04-18 CRITICAL 9.1 CVE-2025-28231 Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privil… Mitigation only Fix from $2,3002025-04-18 MEDIUM 6.5 CVE-2025-32795 Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are impro… Dify 0.6.12+ Fix from $1,6002025-04-18 MEDIUM 6.5 CVE-2025-32796 Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enabl… Dify after 0.6.8 Fix from $1,6002025-04-18 CRITICAL 9.8 CVE-2025-28229 Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator … Optimod 5950 Firmware No fix yet Fix from $2,3002025-04-18 CRITICAL 9.1 CVE-2025-28232 Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without authenticat… Jmb0150 Firmware No fix yet Fix from $2,3002025-04-18 MEDIUM 5.3 CVE-2025-3790 A vulnerability classified as critical has been found in baseweb JSite 1.0. This affects an unknown part of the file /druid/index.html of the compone… Jsite No fix yet Fix from $1,6002025-04-18 CRITICAL 9.8 CVE-2025-3783 A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability i… Web Based Pharmacy Product Management System No fix yet Fix from $2,3002025-04-18 HIGH 8.8 CVE-2025-3764 A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unkno… Web Based Pharmacy Product Management System No fix yet Fix from $1,9502025-04-17 HIGH 8.8 CVE-2025-3765 A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affe… Web Based Pharmacy Product Management System No fix yet Fix from $1,9502025-04-17 CRITICAL 9.0 CVE-2025-3113 A valid, authenticated user with sufficient privileges and who is aware of Continuous Compliance’s internal database configurations can leverage the … Mitigation only Fix from $2,3002025-04-17 HIGH 8.8 CVE-2025-1568 Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit acc… Chrome Os Mitigation only Fix from $1,9502025-04-16 MEDIUM 6.5 CVE-2024-53304 An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands vi… Mitigation only Fix from $1,6002025-04-16 MEDIUM 5.3 CVE-2025-3675 A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been rated as critical. Affected by this issue is the function setL2tpServ… A3700r Firmware No fix yet Fix from $1,6002025-04-16 MEDIUM 5.3 CVE-2025-3674 A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. Affected by this vulnerability is the function … A3700r Firmware No fix yet Fix from $1,6002025-04-16 MEDIUM 5.3 CVE-2025-3668 A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been declared as critical. This vulnerability affects the function setSche… A3700r Firmware No fix yet Fix from $1,6002025-04-16 MEDIUM 5.3 CVE-2025-3667 A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. It has been classified as critical. This affects the function setUPnPCfg of the f… A3700r Firmware No fix yet Fix from $1,6002025-04-16