Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.8 CVE-2025-56396 An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the act… Ruoyi No fix yet Fix from $1,9502025-11-26 HIGH 7.5 CVE-2025-46174 Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserControll… Ruoyi Mitigation only Fix from $1,9502025-11-26 MEDIUM 5.4 CVE-2025-65963 Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow n… Patch available Fix from $1,6002025-11-26 HIGH 8.8 CVE-2025-64064 Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SEC… Project Contract Management Mitigation only Fix from $1,9502025-11-25 HIGH 8.6 CVE-2025-64066 Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any… Project Contract Management Mitigation only Fix from $1,9502025-11-25 HIGH 7.5 CVE-2025-54563 An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Inc… Pingalert Application Server 6.1.1.6+ Fix from $1,9502025-11-24 HIGH 7.5 CVE-2025-54338 An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an … Pingalert Application Server 6.1.1.6+ Fix from $1,9502025-11-24 CRITICAL 9.8 CVE-2025-63958 MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is accessible without authenticatio… Vision Tools Workspace Mitigation only Fix from $2,3002025-11-24 HIGH 8.8 CVE-2025-13573 A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_… Advanced Library Management System No fix yet Fix from $1,9502025-11-24 HIGH 7.2 CVE-2025-13574 A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/add… Online Bidding System No fix yet Fix from $1,9502025-11-24 CRITICAL 9.8 CVE-2025-13544 A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the f… Travel Agency after 2025-07-05 Fix from $2,3002025-11-23 MEDIUM 5.3 CVE-2025-64483 Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configurati… Patch available Fix from $1,6002025-11-21 HIGH 8.0 CVE-2025-64660 Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. Visual Studio Code 1.106.2+ Fix from $1,9502025-11-20 HIGH 8.8 CVE-2025-48986 Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and po… Revive Adserver after 6.0.1 Fix from $1,9502025-11-20 MEDIUM 6.1 CVE-2025-60799 phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manip… Phppgadmin after 7.13.0 Fix from $1,6002025-11-20 MEDIUM 6.5 CVE-2025-13443 A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Pe… Mall after 1.0.3 Fix from $1,6002025-11-20 HIGH 7.2 CVE-2025-13423 A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_prod… Retro Basketball Shoes Online Store No fix yet Fix from $1,9502025-11-20 CRITICAL 9.8 CVE-2025-13411 A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the fil… Retro Basketball Shoes Online Store Mitigation only Fix from $2,3002025-11-19 MEDIUM 6.5 CVE-2025-63214 An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauthorized attackers to delete an… Vbc Server No fix yet Fix from $1,6002025-11-19 CRITICAL 9.1 CVE-2025-63221 The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authentication on the /cgi… Puma Firmware after 1.0.3 Fix from $2,3002025-11-19 CRITICAL 9.8 CVE-2025-63223 The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authenticatio… Streamermax Mk Ii Firmware after 1.0.3 Fix from $2,3002025-11-19 CRITICAL 9.8 CVE-2025-63218 The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authenticat… Wolf1ms Firmware after 1.0.3 Fix from $2,3002025-11-19 HIGH 7.5 CVE-2025-63219 The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home… Iso Fm Firmware No fix yet Fix from $1,9502025-11-19 CRITICAL 9.8 CVE-2025-63225 The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical admi… Elts 100 Firmware Mitigation only Fix from $2,3002025-11-18 MEDIUM 6.5 CVE-2025-56499 Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges… Mihomo No fix yet Fix from $1,6002025-11-18 HIGH 7.8 CVE-2025-37155 A vulnerability in the SSH restricted shell interface of the network management services allows improper access control for authenticated read-only u… Arubaos Cx 10.10.1170 / 10.13.1101+ Fix from $1,9502025-11-18 HIGH 7.5 CVE-2025-41737 Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules. Ewio2 M Firmware 2.2.0+ Fix from $1,9502025-11-18 HIGH 8.8 CVE-2025-13250 A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job… Datax Web after 2.1.2 Fix from $1,9502025-11-16 MEDIUM 6.3 CVE-2025-13249 A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /OfficeServer?isAjaxDownloadTempl… Mitigation only Fix from $1,6002025-11-16 HIGH 8.8 CVE-2025-13238 A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/pro… Flight Booking Software No fix yet Fix from $1,9502025-11-16