Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2025-61115 ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed by ABC Liquors, Inc., contai… Mitigation only Fix from $1,9502025-10-30 HIGH 7.5 CVE-2025-61116 AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arshad, contains an improper acce… Mitigation only Fix from $1,9502025-10-30 HIGH 7.5 CVE-2025-61117 Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an improper access control vulnerabil… Mitigation only Fix from $1,9502025-10-30 HIGH 7.5 CVE-2025-61118 mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper access control vulnerabilities. At… Mitigation only Fix from $1,9502025-10-30 CRITICAL 9.8 CVE-2025-43027 A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attackers to gain administrative a… Mitigation only Fix from $2,3002025-10-30 HIGH 7.5 CVE-2025-61234 Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local network without authentication. Thi… Mitigation only Fix from $1,9502025-10-29 HIGH 7.8 CVE-2025-61156 Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary co… Mitigation only Fix from $1,9502025-10-29 MEDIUM 6.3 CVE-2025-27093 Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev… Patch available Fix from $1,6002025-10-28 HIGH 7.5 CVE-2025-60800 Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via … Jsherp 2025-08-07+ Fix from $1,9502025-10-28 HIGH 7.5 CVE-2025-60354 Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot. Mitigation only Fix from $1,9502025-10-28 CRITICAL 9.8 CVE-2025-12378 A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addprod… Simple Food Ordering System Mitigation only Fix from $2,3002025-10-28 HIGH 8.8 CVE-2025-12347 A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the file application/maxsite/admin/plugins/editor_files… Maxsite Cms after 109 Fix from $1,9502025-10-28 HIGH 8.8 CVE-2025-12346 A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of the file application/maxsite/admin/plugins/auto_pos… Maxsite Cms after 109 Fix from $1,9502025-10-28 MEDIUM 6.3 CVE-2025-12344 A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown function of the file /service/NCloudGatewayServlet … Mitigation only Fix from $1,6002025-10-28 HIGH 7.2 CVE-2025-12331 A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unr… Willow Cms after 1.4.0 Fix from $1,9502025-10-27 MEDIUM 5.4 CVE-2025-60982 IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object references. Affected endpoints… Mitigation only Fix from $1,6002025-10-27 CRITICAL 9.8 CVE-2025-12301 A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct… Simple Food Ordering System Mitigation only Fix from $2,3002025-10-27 HIGH 8.8 CVE-2025-54968 An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may … Socet Gxp 4.6.0.2+ Fix from $1,9502025-10-27 MEDIUM 6.5 CVE-2025-54970 An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some configurations, thi… Socet Gxp 4.6.0.2+ Fix from $1,6002025-10-27 MEDIUM 5.3 CVE-2023-37749 Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorizati… Mitigation only Fix from $1,6002025-10-27 CRITICAL 9.1 CVE-2025-60291 An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access s… Mitigation only Fix from $2,3002025-10-27 HIGH 7.5 CVE-2025-12276 A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of th… Learnhouse after 2025-09-21 Fix from $1,9502025-10-27 CRITICAL 9.8 CVE-2025-12268 A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/cour… Learnhouse after 2025-09-21 Fix from $2,3002025-10-27 HIGH 8.8 CVE-2025-12223 A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the co… Flight Booking Software after 3.1 Fix from $1,9502025-10-27 HIGH 8.8 CVE-2025-12222 A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected by this issue is some unknown functionality of the f… Flight Booking Software after 3.1 Fix from $1,9502025-10-27 HIGH 7.2 CVE-2025-12201 A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1. This affects an unknown part… User Management Php Mysql after 2023-03-16 Fix from $1,9502025-10-27 HIGH 8.8 CVE-2025-59500 Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network. Azure Notification Service Mitigation only Fix from $1,9502025-10-23 CRITICAL 9.8 CVE-2025-59273 Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network. Azure Event Grid No fix yet Fix from $2,3002025-10-23 HIGH 7.2 CVE-2025-62713 Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE… Patch available Fix from $1,9502025-10-23 HIGH 7.2 CVE-2025-62290 Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected … Zfs Storage Appliance Kit Mitigation only Fix from $1,9502025-10-21