Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.2 CVE-2025-13185 A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. … News365 after 7.0.3 Fix from $1,9502025-11-14 CRITICAL 10.0 CVE-2025-54339 An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remo… Pingalert Application Server 6.1.1.4+ Fix from $2,3002025-11-14 CRITICAL 9.6 CVE-2025-54343 An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remo… Pingalert Application Server 6.1.1.4+ Fix from $2,3002025-11-14 MEDIUM 5.4 CVE-2025-64746 Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-… Directus 11.13.0+ Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-47220 A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in… Signserver 7.3.1+ Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-47221 An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_… Signserver 7.3.1+ Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-47222 A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring … Signserver 7.3.1+ Fix from $1,6002025-11-13 MEDIUM 5.5 CVE-2025-46362 Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain an Improper Access Control vulnerability. A low privileged attacker wi… Alienware Command Center 6.10.15.0+ Fix from $1,6002025-11-13 HIGH 8.8 CVE-2025-43515 The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauthenticated user on the same ne… Compressor 4.11.1+ Fix from $1,9502025-11-13 HIGH 7.5 CVE-2025-64706 Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerabil… Typebot 3.13.0+ Fix from $1,9502025-11-13 HIGH 8.8 CVE-2025-20341 A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an… Mitigation only Fix from $1,9502025-11-13 HIGH 7.2 CVE-2025-46608 Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access co… Data Lakehouse 1.6.0.0+ Fix from $1,9502025-11-12 HIGH 8.8 CVE-2025-13061 A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /index.php?page=manage_voting. Pe… Online Voting System No fix yet Fix from $1,9502025-11-12 CRITICAL 9.8 CVE-2025-63353 A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted fr… Hg6145f1 Firmware Mitigation only Fix from $2,3002025-11-12 CRITICAL 9.8 CVE-2025-63666 Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suf… Ac15 Firmware Mitigation only Fix from $2,3002025-11-12 HIGH 7.5 CVE-2025-63667 Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API en… Ip Camera Firmware Mitigation only Fix from $1,9502025-11-12 HIGH 7.8 CVE-2025-60705 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.8 CVE-2025-59512 Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 MEDIUM 6.7 CVE-2025-47179 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. Configuration Manager 2403 5.00.9128.1037 / 5.00.9132.1031+ Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-22391 Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged so… No fix yet Fix from $1,6002025-11-11 MEDIUM 6.5 CVE-2025-60876 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request lin… Busybox after 1.37.0 Fix from $1,6002025-11-10 CRITICAL 9.1 CVE-2025-12480 KEVEPSS 91% Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after se… Triofox 16.7.10368.56560+ Fix from $2,3002025-11-10 HIGH 7.5 CVE-2025-64347 Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and bel… Patch available Fix from $1,9502025-11-07 CRITICAL 9.8 CVE-2025-12862 A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /… Online Notes Sharing Platform Mitigation only Fix from $2,3002025-11-07 MEDIUM 6.5 CVE-2025-63686 There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c9381162afbaa95 (2020-11-23) in the … Personmanage after 1.0 Fix from $1,6002025-11-07 HIGH 8.2 CVE-2025-27919 An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk set… Anydesk after 9.0.4 Fix from $1,9502025-11-06 MEDIUM 6.5 CVE-2025-12808 Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values,… Devolutions Server 2025.2.17.0 / 2025.3.6.0+ Fix from $1,6002025-11-06 MEDIUM 6.5 CVE-2025-60784 A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.php Pay m… Voluntary Like System No fix yet Fix from $1,6002025-11-05 HIGH 8.8 CVE-2025-57130 An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escal… Zwiicms after 13.6.07 Fix from $1,9502025-11-05 MEDIUM 5.4 CVE-2025-58337 An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, allowing modifications that s… Doris Mcp Server 0.6.0+ Fix from $1,6002025-11-05