Vulnerability index

Browse CVEs

5,903 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.5 CVE-2025-46282 The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app may be able to access sensit… Safari 26.2+ Fix from $1,6002025-12-17 HIGH 8.3 CVE-2025-66397 ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk func… Churchcrm 6.5.3+ Fix from $1,9502025-12-17 MEDIUM 6.8 CVE-2025-14095 A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user … Mitigation only Fix from $1,6002025-12-17 HIGH 7.0 CVE-2025-11901 An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z59… Mitigation only Fix from $1,9502025-12-17 MEDIUM 5.4 CVE-2025-14748 A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVI… Tc155 Firmware No fix yet Fix from $1,6002025-12-16 HIGH 8.8 CVE-2025-14749 A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVI… Tc155 Firmware No fix yet Fix from $1,9502025-12-16 CRITICAL 9.1 CVE-2025-55895 TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6448_B20240521 and V9.3.5u.6437_B20230519 are vulnerable to Incorrect Access Control. Atta… A3300r Firmware No fix yet Fix from $2,3002025-12-15 HIGH 7.5 CVE-2025-65176 An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a machine where OneAgent is inst… Oneagent 1.325.47+ Fix from $1,9502025-12-15 HIGH 7.5 CVE-2025-65779 An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticated attackers can update a boar… Wekan 8.16+ Fix from $1,9502025-12-15 HIGH 8.8 CVE-2025-65780 An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated users can update their entire… Wekan 8.16+ Fix from $1,9502025-12-15 MEDIUM 5.6 CVE-2025-14660 A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mc… Patch available Fix from $1,6002025-12-14 HIGH 7.2 CVE-2025-14642 A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. … Computer Laboratory System No fix yet Fix from $1,9502025-12-14 HIGH 7.2 CVE-2025-14641 A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. Th… Computer Laboratory System No fix yet Fix from $1,9502025-12-14 CRITICAL 9.8 CVE-2025-14583 A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing … Online Student Enrollment System Mitigation only Fix from $2,3002025-12-12 HIGH 7.2 CVE-2025-14582 A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=us… Online Student Enrollment System No fix yet Fix from $1,9502025-12-12 MEDIUM 5.5 CVE-2025-43513 A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2… macOS 14.8.3 / 15.7.3+ Fix from $1,6002025-12-12 MEDIUM 5.5 CVE-2025-43416 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app ma… macOS 14.8.3 / 15.7.3+ Fix from $1,6002025-12-12 MEDIUM 5.5 CVE-2025-43351 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user … macOS 26.1+ Fix from $1,6002025-12-12 MEDIUM 5.2 CVE-2025-43393 A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of i… macOS 26.1+ Fix from $1,6002025-12-12 CRITICAL 9.1 CVE-2025-66430 Plesk 18.0 has Incorrect Access Control. Plesk 18.0.73.5 / 18.0.74.2+ Fix from $2,3002025-12-12 HIGH 7.8 CVE-2025-64669 Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. Windows Admin Center 2511+ Fix from $1,9502025-12-11 HIGH 7.2 CVE-2025-14530 A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin… Real Estate Property Listing App No fix yet Fix from $1,9502025-12-11 HIGH 7.5 CVE-2025-14528 A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Han… Dir 803 Firmware after 1.04 Fix from $1,9502025-12-11 CRITICAL 9.8 CVE-2025-14522 A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /… Hfly after 2016-05-11 Fix from $2,3002025-12-11 CRITICAL 9.4 CVE-2025-67510 Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided … Neuron 2.8.12+ Fix from $2,3002025-12-10 HIGH 7.6 CVE-2025-24857 Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018… U Boot 2017.11+ Fix from $1,9502025-12-10 MEDIUM 5.6 CVE-2025-64897 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could le… Coldfusion Mitigation only Fix from $1,6002025-12-10 HIGH 8.1 CVE-2025-65594 OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthori… Opensis after 9.2 Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-64673 Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8146 / 10.0.19044.6691+ Fix from $1,9502025-12-09 MEDIUM 5.5 CVE-2025-62570 Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally. Windows 11 24h2 10.0.26100.7392 / 10.0.26200.7392+ Fix from $1,6002025-12-09