Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2024-46430 Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthent… W18e Firmware No fix yet Fix from $1,6002025-02-10 HIGH 8.8 CVE-2024-46432 Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgW… W18e Firmware No fix yet Fix from $1,9502025-02-10 MEDIUM 5.5 CVE-2025-1115 A vulnerability classified as problematic was found in RT-Thread up to 5.1.0. Affected by this vulnerability is the function sys_device_close/sys_dev… Rt Thread after 5.1.0 Fix from $1,6002025-02-08 HIGH 7.7 CVE-2022-26389 An improper access control vulnerability may allow privilege escalation.This issue affects:  * ELI 380 Resting Electrocardiograph: Versions 2.6.… Mitigation only Fix from $1,9502025-02-07 MEDIUM 6.5 CVE-2024-57249 Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthorized access via exploiting a … Filevista No fix yet Fix from $1,6002025-02-07 HIGH 7.5 CVE-2024-56889 Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrari… Complaint Management System No fix yet Fix from $1,9502025-02-06 HIGH 8.8 CVE-2025-24968 reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific … Rengine after 2.2.0 Fix from $1,9502025-02-04 HIGH 7.8 CVE-2024-35177 Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premise… Wazuh 4.9.0+ Fix from $1,9502025-02-03 HIGH 8.8 CVE-2024-56898 Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform action… Mitigation only Fix from $1,9502025-02-03 MEDIUM 5.1 CVE-2023-52164 access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no … Mitigation only Fix from $1,6002025-02-03 HIGH 7.5 CVE-2024-57433 macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available a… Mall Tiny No fix yet Fix from $1,9502025-01-31 HIGH 8.8 CVE-2024-23920 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. … Home Flex Nema 14 50 Plug Firmware Mitigation only Fix from $1,9502025-01-31 HIGH 7.6 CVE-2025-24885 pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rende… Mitigation only Fix from $1,9502025-01-30 MEDIUM 6.5 CVE-2025-23367 A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured usin… Jboss Enterprise Application Platform 7.4.21 / 8.0.7+ Fix from $1,6002025-01-30 MEDIUM 6.5 CVE-2025-0742 An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files… Embedai 2.1+ Fix from $1,6002025-01-30 MEDIUM 6.5 CVE-2025-0744 an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subs… Embedai 2.1+ Fix from $1,6002025-01-30 MEDIUM 6.5 CVE-2025-0745 An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the b… Embedai 2.1+ Fix from $1,6002025-01-30 MEDIUM 6.5 CVE-2025-0739 An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscri… Embedai 2.1+ Fix from $1,6002025-01-30 MEDIUM 6.5 CVE-2025-0740 An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain cha… Embedai 2.1+ Fix from $1,6002025-01-30 MEDIUM 5.3 CVE-2024-13457 The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.… Event Tickets 5.18.1.1+ Fix from $1,6002025-01-30 HIGH 8.1 CVE-2025-0802 A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this vulnerability is an unknown … Best Employee Management System No fix yet Fix from $1,9502025-01-29 MEDIUM 6.3 CVE-2025-0783 A vulnerability, which was classified as problematic, was found in pankajindevops scale up to 20241113. This affects an unknown part of the component… Mitigation only Fix from $1,6002025-01-28 HIGH 7.5 CVE-2025-24365 vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other o… Vaultwarden 1.33.0+ Fix from $1,9502025-01-27 HIGH 7.2 CVE-2025-0722 A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.p… Image Gallery Management System No fix yet Fix from $1,9502025-01-27 HIGH 8.8 CVE-2025-0702 A vulnerability classified as critical was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This vulnerability affects unk… Bootplus after 2020-08-24 Fix from $1,9502025-01-24 HIGH 8.1 CVE-2025-0650 A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations … Mitigation only Fix from $1,9502025-01-23 HIGH 7.7 CVE-2025-23083 With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers… Mitigation only Fix from $1,9502025-01-22 MEDIUM 5.5 CVE-2024-57360 https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm … Mitigation only Fix from $1,6002025-01-21 HIGH 7.2 CVE-2025-0582 A vulnerability classified as critical was found in itsourcecode Farm Management System up to 1.0. This vulnerability affects unknown code of the fil… Tailoring Management System No fix yet Fix from $1,9502025-01-20 MEDIUM 6.5 CVE-2025-21185 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Edge Chromium 132.0.2957.115+ Fix from $1,6002025-01-17