Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.1 CVE-2025-2280 Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass th… Devolutions Server 2024.3.6.0+ Fix from $1,9502025-03-13 MEDIUM 5.6 CVE-2025-25683 AlekSIS-Core is vulnerable to Incorrect Access Control. Unauthenticated users can access all PDF files. This affects AlekSIS-Core 3.0, 3.1, 3.1.1, 3.… Mitigation only Fix from $1,6002025-03-12 MEDIUM 5.8 CVE-2025-20144 A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote at… Ios Xr Mitigation only Fix from $1,6002025-03-12 CRITICAL 9.8 CVE-2025-2218 A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /… Lovecards after 2.3.2 Fix from $2,3002025-03-12 CRITICAL 9.8 CVE-2025-2219 A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /ap… Lovecards after 2.3.2 Fix from $2,3002025-03-12 CRITICAL 9.8 CVE-2025-2216 A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the… Warehouse Refinement Management System No fix yet Fix from $2,3002025-03-12 CRITICAL 9.8 CVE-2025-23242 NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead… Riva 2.19.0+ Fix from $2,3002025-03-11 CRITICAL 9.1 CVE-2025-23243 NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead… Riva 2.19.0+ Fix from $2,3002025-03-11 HIGH 8.8 CVE-2025-26645 Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. Windows 10 1507 10.0.10240.20947 / 10.0.14393.7876+ Fix from $1,9502025-03-11 HIGH 7.3 CVE-2025-24994 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5039 / 10.0.22631.5039+ Fix from $1,9502025-03-11 HIGH 7.3 CVE-2025-24076 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. Windows 11 22h2 10.0.22621.5039 / 10.0.22631.5039+ Fix from $1,9502025-03-11 HIGH 7.8 CVE-2024-9157 ** UNSUPPORTED WHEN ASSIGNED **  A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local… Mitigation only Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-25614 Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers. Unifiedtransform No fix yet Fix from $1,9502025-03-10 HIGH 8.8 CVE-2025-2121 A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the compon… F800 Pro Firmware No fix yet Fix from $1,9502025-03-09 CRITICAL 9.8 CVE-2025-2115 A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRe… Warehouse Refinement Management System No fix yet Fix from $2,3002025-03-09 MEDIUM 5.4 CVE-2025-2089 A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUse… Starsea Mall No fix yet Fix from $1,6002025-03-07 HIGH 7.5 CVE-2025-25381 Incorrect access control in the KSRTC AWATAR app of Karnataka State Road Transport Corporation v1.3.0 allows to view sensitive information such as us… Mitigation only Fix from $1,9502025-03-06 CRITICAL 9.8 CVE-2025-2035 A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality… Ecommerce Website Using Php No fix yet Fix from $2,3002025-03-06 HIGH 7.6 CVE-2025-2031 A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile of the file /dev-api/cms/file/… Chestnutcms No fix yet Fix from $1,9502025-03-06 MEDIUM 6.3 CVE-2024-56195 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.8, from 10.0.0 thro… Traffic Server 9.2.9 / 10.0.4+ Fix from $1,6002025-03-06 MEDIUM 6.3 CVE-2024-56196 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are rec… Traffic Server 10.0.4+ Fix from $1,6002025-03-06 CRITICAL 9.8 CVE-2025-27646 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Edit User Account Exposure V-2024-001. Vasion Print 20.0.2253 / 22.0.913+ Fix from $2,3002025-03-05 CRITICAL 9.8 CVE-2025-27649 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.893 Application 20.0.2140 allows Incorrect Access Control: PHP V-2023-016. Vasion Print 20.0.2140 / 22.0.893+ Fix from $2,3002025-03-05 HIGH 7.7 CVE-2025-1259 On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can resu… No fix yet Fix from $1,9502025-03-04 CRITICAL 9.1 CVE-2025-1260 On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can resu… No fix yet Fix from $2,3002025-03-04 MEDIUM 5.3 CVE-2020-3122 A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthent… Asyncos Mitigation only Fix from $1,6002025-03-04 CRITICAL 9.1 CVE-2025-1941 Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE… Firefox 136.0+ Fix from $2,3002025-03-04 CRITICAL 9.8 CVE-2025-1890 A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/ma… Shishuocms No fix yet Fix from $2,3002025-03-04 HIGH 7.0 CVE-2025-1882 A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality … I11 Firmware after 20250227 Fix from $1,9502025-03-03 HIGH 8.5 CVE-2024-51954 There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allo… Arcgis Server after 11.3 Fix from $1,9502025-03-03