Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.2 CVE-2025-59932 Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE … Flagforge 2.3.1+ Fix from $1,9502025-09-27 HIGH 7.5 CVE-2025-11028 A security flaw has been discovered in givanz Vvveb up to 1.0.7.2. This affects an unknown part of the component Image Handler. Performing manipulati… Vvveb after 1.0.7.2 Fix from $1,9502025-09-26 HIGH 7.5 CVE-2025-11026 A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality of the component Configurati… Vvveb after 1.0.7.2 Fix from $1,9502025-09-26 HIGH 7.5 CVE-2025-48707 An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared amo… Stormshield Network Security 5.0.1+ Fix from $1,9502025-09-25 MEDIUM 5.3 CVE-2025-10952 A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream… Mitigation only Fix from $1,6002025-09-25 HIGH 8.7 CVE-2025-10957 This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could explo… Mitigation only Fix from $1,9502025-09-25 HIGH 7.5 CVE-2025-56241EPSS 6% Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a … No fix yet Fix from $1,9502025-09-24 HIGH 7.5 CVE-2025-48869 Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by… Horilla No fix yet Fix from $1,9502025-09-24 MEDIUM 5.3 CVE-2025-20316 A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow … Mitigation only Fix from $1,6002025-09-24 MEDIUM 5.8 CVE-2025-20339 A vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote att… Mitigation only Fix from $1,6002025-09-24 MEDIUM 5.3 CVE-2025-7106 danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/… Librechat 0.7.9+ Fix from $1,6002025-09-23 CRITICAL 9.6 CVE-2025-59434 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated … Mitigation only Fix from $2,3002025-09-22 MEDIUM 6.8 CVE-2025-57438 The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only afte… Ip 4c Firmware No fix yet Fix from $1,6002025-09-22 HIGH 7.7 CVE-2025-5962 A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to access and manipulate the chat h… Mitigation only Fix from $1,9502025-09-22 MEDIUM 6.3 CVE-2025-10763 A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by this issue is some unknown func… Mitigation only Fix from $1,6002025-09-21 MEDIUM 6.3 CVE-2025-10755 A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component Content-Type Handler. The ma… Mitigation only Fix from $1,6002025-09-20 MEDIUM 6.3 CVE-2025-10741 A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown function of the component Profile … Mitigation only Fix from $1,6002025-09-20 MEDIUM 6.3 CVE-2025-10669 A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component Playlist Upload Handler. Per… Mitigation only Fix from $1,6002025-09-18 HIGH 7.5 CVE-2025-23329 NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corruption by identifying and acce… Triton Inference Server 25.08+ Fix from $1,9502025-09-17 HIGH 8.8 CVE-2025-10616 A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipul… E Commerce Website No fix yet Fix from $1,9502025-09-17 HIGH 8.8 CVE-2025-10615 A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipula… E Commerce Website No fix yet Fix from $1,9502025-09-17 HIGH 8.8 CVE-2025-10608 A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Perform… I Educar after 2.10.0 Fix from $1,9502025-09-17 MEDIUM 6.5 CVE-2025-10607 A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi… I Educar after 2.10.0 Fix from $1,6002025-09-17 CRITICAL 9.8 CVE-2025-10600 A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /register.php. This manipulatio… Online Exam Form Submission Mitigation only Fix from $2,3002025-09-17 HIGH 7.5 CVE-2025-37125 A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass… Mitigation only Fix from $1,9502025-09-16 CRITICAL 9.1 CVE-2025-54391 A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with valid user credentials to bypas… Mitigation only Fix from $2,3002025-09-16 HIGH 8.1 CVE-2025-59333 The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-server, fails to implement ade… Mcp Database Server after 1.1.0 Fix from $1,9502025-09-16 MEDIUM 5.5 CVE-2025-43369 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26. An app may be able to access protected user data. macOS 26.0+ Fix from $1,6002025-09-15 HIGH 8.2 CVE-2025-43371 This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox. Xcode 26.0+ Fix from $1,9502025-09-15 MEDIUM 5.5 CVE-2025-43337 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26. An app may be able t… macOS 26.0+ Fix from $1,6002025-09-15