Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.3 CVE-2025-14197 A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3. The impacted element is an unknown function of the file /rest/f/api/res… Mitigation only Fix from $1,6002025-12-07 HIGH 8.8 CVE-2025-14195 A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/a… Employee Profile Management System No fix yet Fix from $1,9502025-12-07 HIGH 8.8 CVE-2025-14086 A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipul… Youlai Mall No fix yet Fix from $1,9502025-12-05 MEDIUM 6.5 CVE-2025-14052 A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-… Youlai Mall No fix yet Fix from $1,6002025-12-05 CRITICAL 9.8 CVE-2025-66509 LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowin… Lara Dashboard after 2.3.0 Fix from $2,3002025-12-04 HIGH 7.5 CVE-2025-63363 A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage … Rs232\/485 To Wifi Eth \(b\) Firmware No fix yet Fix from $1,9502025-12-04 HIGH 7.5 CVE-2025-57210 Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspecified v… Platform Mitigation only Fix from $1,9502025-12-04 HIGH 7.5 CVE-2025-57212 Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a crafted requ… Platform Mitigation only Fix from $1,9502025-12-04 HIGH 7.5 CVE-2025-57213 Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via a crafted … Platform Mitigation only Fix from $1,9502025-12-04 MEDIUM 6.5 CVE-2025-65097 RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4… Romm 4.4.1+ Fix from $1,6002025-12-03 MEDIUM 6.2 CVE-2025-65841 Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings … Aquarius No fix yet Fix from $1,6002025-12-03 MEDIUM 6.3 CVE-2025-13949 A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /server/controller/FileController.… Mitigation only Fix from $1,6002025-12-03 CRITICAL 9.1 CVE-2025-59703 Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to access the internal compo… Nshield 5c Firmware 13.6.12 / 13.9.0+ Fix from $2,3002025-12-02 HIGH 7.2 CVE-2025-59697 Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by ed… Nshield 5c Firmware 13.6.12 / 13.9.0+ Fix from $1,9502025-12-02 HIGH 7.2 CVE-2025-59702 Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with elevated privileges to … Nshield 5c Firmware 13.6.12 / 13.9.0+ Fix from $1,9502025-12-02 HIGH 7.5 CVE-2025-55749 XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJ… Xwiki 16.10.11 / 17.4.4+ Fix from $1,9502025-12-01 HIGH 7.8 CVE-2025-61229 An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight … Superduper\! after 3.10 Fix from $1,9502025-12-01 HIGH 8.1 CVE-2025-57489 Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improp… Superduper\! Mitigation only Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-63525 An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted… Blood Bank Management System No fix yet Fix from $1,9502025-12-01 CRITICAL 9.8 CVE-2025-13815 A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This man… Mogublog after 5.2 Fix from $2,3002025-12-01 MEDIUM 6.5 CVE-2025-13785 A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the … Skuul after 2.6.5 Fix from $1,6002025-11-30 HIGH 8.4 CVE-2025-66223 OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid… Mitigation only Fix from $1,9502025-11-29 MEDIUM 6.5 CVE-2025-66027 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant detai… Rallly 4.5.6+ Fix from $1,6002025-11-29 MEDIUM 5.5 CVE-2025-64715 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetw… Cilium 1.16.17 / 1.17.10+ Fix from $1,6002025-11-29 CRITICAL 9.8 CVE-2025-65276 An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru comm… Hashtech after 2021-07-02 Fix from $2,3002025-11-26 HIGH 8.2 CVE-2025-66028 OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via L… Oneuptime 8.0.5567+ Fix from $1,9502025-11-26 CRITICAL 9.8 CVE-2025-55469 Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend. Youlai Boot Mitigation only Fix from $2,3002025-11-26 HIGH 7.5 CVE-2025-55471 Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users. Youlai Boot No fix yet Fix from $1,9502025-11-26 MEDIUM 6.5 CVE-2025-65238 Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 allows attackers with l… Ussd Gateway No fix yet Fix from $1,6002025-11-26 HIGH 7.5 CVE-2025-46175 Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserContr… Ruoyi Mitigation only Fix from $1,9502025-11-26