Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.1 CVE-2025-25948EPSS 7% Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v… Student Information System No fix yet Fix from $2,3002025-03-03 HIGH 8.1 CVE-2025-25950 Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v… Academia Student Information System Mitigation only Fix from $1,9502025-03-03 MEDIUM 6.3 CVE-2025-1835 A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the function upload of the file /ap… Mitigation only Fix from $1,6002025-03-02 CRITICAL 9.8 CVE-2025-1834 A vulnerability, which was classified as critical, was found in zj1983 zz up to 2024-8. This affects an unknown part of the file /resolve. The manipu… Zz after 2024-8 Fix from $2,3002025-03-02 CRITICAL 9.8 CVE-2025-1818 A vulnerability, which was classified as critical, has been found in zj1983 zz up to 2024-8. This issue affects some unknown processing of the file s… Zz after 2024-8 Fix from $2,3002025-03-02 CRITICAL 9.8 CVE-2025-1791 A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vend… Skycaiji Mitigation only Fix from $2,3002025-03-01 CRITICAL 9.8 CVE-2024-37566 Infoblox NIOS through 8.6.4 has Improper Authentication for Grids. Nios after 8.6.4 Fix from $2,3002025-02-27 CRITICAL 9.1 CVE-2024-37567 Infoblox NIOS through 8.6.4 has Improper Access Control for Grids. Nios after 8.6.4 Fix from $2,3002025-02-27 HIGH 8.8 CVE-2024-38291 In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation. Xiq Se 24.2.11+ Fix from $1,9502025-02-27 CRITICAL 9.8 CVE-2024-53573 Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for admi… Unifiedtransform No fix yet Fix from $2,3002025-02-26 MEDIUM 6.5 CVE-2024-36259 Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive inf… Odoo No fix yet Fix from $1,6002025-02-25 HIGH 8.8 CVE-2024-12368 Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens o… Odoo No fix yet Fix from $1,9502025-02-25 MEDIUM 5.3 CVE-2024-13693 The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-export-class.php in all version… Enfold 7.0+ Fix from $1,6002025-02-25 HIGH 7.3 CVE-2025-1646 A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unknown functionality of the file … Mitigation only Fix from $1,9502025-02-25 MEDIUM 6.5 CVE-2024-53542 Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows at… Mitigation only Fix from $1,6002025-02-24 CRITICAL 9.8 CVE-2025-27140 WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA app… Wegia 3.2.15+ Fix from $2,3002025-02-24 CRITICAL 9.8 CVE-2025-1598 A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been declared as critical. Affected by this vulnerability is … Best Church Management Software No fix yet Fix from $2,3002025-02-24 HIGH 7.5 CVE-2025-1606 A vulnerability classified as problematic was found in SourceCodester Best Employee Management System 1.0. This vulnerability affects unknown code of… Best Employee Management System No fix yet Fix from $1,9502025-02-24 MEDIUM 5.3 CVE-2025-1595 A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. This vulnerability affects un… No fix yet Fix from $1,6002025-02-23 CRITICAL 9.8 CVE-2025-1593 A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file… Best Employee Management System Mitigation only Fix from $2,3002025-02-23 HIGH 7.2 CVE-2025-1590 A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /a… E Learning System Mitigation only Fix from $1,9502025-02-23 CRITICAL 9.8 CVE-2025-1555 A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. … Education And Training System Mitigation only Fix from $2,3002025-02-21 MEDIUM 6.0 CVE-2025-25968 DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive infor… Cm3 Acora Content Management System Mitigation only Fix from $1,6002025-02-20 HIGH 7.8 CVE-2025-21105 Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could pote… Recoverpoint For Virtual Machines Mitigation only Fix from $1,9502025-02-20 CRITICAL 9.8 CVE-2025-24989 KEV An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th… Power Pages Patch available Fix from $2,3002025-02-19 CRITICAL 9.1 CVE-2020-35546 Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings. Mitigation only Fix from $2,3002025-02-19 MEDIUM 5.3 CVE-2025-20153 A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configur… Secure Email Gateway Mitigation only Fix from $1,6002025-02-19 MEDIUM 5.3 CVE-2025-0968 The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 du… Elementskit Elementor Addons 3.4.1+ Fix from $1,6002025-02-19 HIGH 7.5 CVE-2025-26616 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the … Wegia 3.2.14+ Fix from $1,9502025-02-18 CRITICAL 9.8 CVE-2025-26617 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W… Wegia 3.2.14+ Fix from $2,3002025-02-18