Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2026-0566 A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_po… Content Management System Mitigation only Fix from $2,3002026-01-02 HIGH 8.8 CVE-2026-0547 A vulnerability was found in PHPGurukul Online Course Registration up to 3.1. This issue affects some unknown processing of the file /admin/edit-stud… Online Course Registration after 3.1 Fix from $1,9502026-01-02 HIGH 7.3 CVE-2025-15426 A vulnerability was identified in jackying H-ui.admin up to 3.1. This affects an unknown function in the library /lib/webuploader/0.1.5/server/previe… No fix yet Fix from $1,9502026-01-02 HIGH 8.8 CVE-2025-15423 A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Suc… Empirecms after 8.0 Fix from $1,9502026-01-02 MEDIUM 5.4 CVE-2025-15415 A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the… Wangmarket after 6.4 Fix from $1,6002026-01-01 HIGH 8.8 CVE-2025-15404 A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /s… School File Management System No fix yet Fix from $1,9502026-01-01 HIGH 7.2 CVE-2025-15360 A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd/newbee/mall/controller/commo… Newbee Mall Plus No fix yet Fix from $1,9502025-12-30 MEDIUM 6.7 CVE-2025-69257 theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loa… Patch available Fix from $1,6002025-12-30 HIGH 7.2 CVE-2025-15262 A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/edit.php of the component S… Simple Php Cms No fix yet Fix from $1,9502025-12-30 MEDIUM 5.4 CVE-2023-32238 Vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery).This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem… No fix yet Fix from $1,6002025-12-30 HIGH 8.8 CVE-2025-15199 A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboar… College Notes Uploading System Mitigation only Fix from $1,9502025-12-29 HIGH 7.2 CVE-2025-15197 A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown co… News Buzz No fix yet Fix from $1,9502025-12-29 MEDIUM 6.3 CVE-2025-15152 A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability affects the function addProduc… Mitigation only Fix from $1,6002025-12-28 HIGH 7.2 CVE-2025-15110 A vulnerability has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. Affected is the function Upload of the file Admin/Home/C… Xcms No fix yet Fix from $1,9502025-12-27 HIGH 7.3 CVE-2025-15109 A flaw has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. This impacts an unknown function of the file Public/javascripts/a… Mitigation only Fix from $1,9502025-12-27 HIGH 7.5 CVE-2025-67014 Incorrect access control in DEV Systemtechnik GmbH DEV 7113 RF over Fiber Distribution System 32-0078 H.01 allows unauthenticated attackers to access… Dev7113 Firmware No fix yet Fix from $1,9502025-12-26 HIGH 7.5 CVE-2025-67015 Incorrect access control in Comtech EF Data CDM-625 / CDM-625A Advanced Satellite Modem with firmware v2.5.1 allows attackers to change the Administr… Cdm 625 Firmware No fix yet Fix from $1,9502025-12-26 HIGH 7.5 CVE-2025-15082 A vulnerability was found in TOZED ZLT M30s up to 1.47. Impacted is an unknown function of the file /reqproc/proc_post of the component Web Managemen… Zlt M30s Firmware after 1.47 Fix from $1,9502025-12-25 HIGH 8.8 CVE-2025-15050 A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.p… Student File Management System No fix yet Fix from $1,9502025-12-24 HIGH 7.5 CVE-2025-66735 youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks,… Youlai Boot Patch available Fix from $1,9502025-12-22 HIGH 7.1 CVE-2025-66736 youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check… Youlai Boot Patch available Fix from $1,9502025-12-22 HIGH 7.5 CVE-2025-63663 Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other… Gt Edge Ai 2.0.12+ Fix from $1,9502025-12-22 HIGH 7.5 CVE-2025-63664 Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to acces… Gt Edge Ai 2.0.12+ Fix from $1,9502025-12-22 HIGH 8.8 CVE-2025-15009 A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/com… Chestnutcms after 1.5.8 Fix from $1,9502025-12-22 MEDIUM 6.5 CVE-2025-66911 Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handle… Turms No fix yet Fix from $1,6002025-12-19 HIGH 7.5 CVE-2025-63387EPSS 30% Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-feature… Dify Patch available Fix from $1,9502025-12-18 HIGH 8.8 CVE-2025-14885 A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the compon… Client Database Management System No fix yet Fix from $1,9502025-12-18 MEDIUM 5.3 CVE-2025-67789 An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer co… Drivelock 24.1.6 / 24.2.7+ Fix from $1,6002025-12-17 MEDIUM 5.5 CVE-2025-46288 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, wat… Ipados 26.2+ Fix from $1,6002025-12-17 MEDIUM 5.5 CVE-2025-46292 This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app ma… Ipados 18.7.3 / 26.2+ Fix from $1,6002025-12-17