Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2022-43110 Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspe… Mitigation only Fix from $2,3002025-08-22 CRITICAL 9.8 CVE-2024-53496 Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication. My Site Mitigation only Fix from $2,3002025-08-22 MEDIUM 5.3 CVE-2025-55626 An Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_25031222… Mitigation only Fix from $1,6002025-08-22 HIGH 7.3 CVE-2025-55630 A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662… Smart 2k\+ Plug In Wi Fi Video Doorbell With Chime Firmware No fix yet Fix from $1,9502025-08-22 HIGH 7.5 CVE-2024-53494 Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication. Mitigation only Fix from $1,9502025-08-22 HIGH 8.1 CVE-2025-55741 UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the… Unopim 0.3.1+ Fix from $1,9502025-08-22 CRITICAL 9.8 CVE-2025-53763 Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. Purview Data Governance No fix yet Fix from $2,3002025-08-21 HIGH 8.3 CVE-2025-7051 On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This … N Central 2025.2+ Fix from $1,9502025-08-21 CRITICAL 9.1 CVE-2024-45438 An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within … Mitigation only Fix from $2,3002025-08-21 MEDIUM 5.3 CVE-2025-55371 Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the informatio… Jsherp No fix yet Fix from $1,6002025-08-21 MEDIUM 5.3 CVE-2025-55366 Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords… Jsherp No fix yet Fix from $1,6002025-08-21 MEDIUM 5.3 CVE-2025-55367 Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the … Jsherp No fix yet Fix from $1,6002025-08-21 HIGH 8.8 CVE-2025-55368 Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supp… Jsherp No fix yet Fix from $1,9502025-08-21 CRITICAL 9.8 CVE-2025-9296 A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_a… Emlog after 2.5.18 Fix from $2,3002025-08-21 HIGH 8.1 CVE-2025-27215 An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported c… Mitigation only Fix from $1,9502025-08-21 CRITICAL 9.8 CVE-2024-57155 Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token. Mitigation only Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2024-57154 Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index. Mitigation only Fix from $2,3002025-08-20 HIGH 7.5 CVE-2024-57152 Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the c… My Site No fix yet Fix from $1,9502025-08-20 HIGH 7.5 CVE-2024-53495 Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication. My Site No fix yet Fix from $1,9502025-08-20 HIGH 8.6 CVE-2025-28041 Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication. Itranswarp after 2.19 Fix from $1,9502025-08-20 CRITICAL 9.8 CVE-2024-57157 Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token. Mitigation only Fix from $2,3002025-08-20 HIGH 8.8 CVE-2025-9153 A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin… Online Tour \& Travel Management System No fix yet Fix from $1,9502025-08-19 MEDIUM 5.3 CVE-2025-50434 A security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is related to incorrect access … No fix yet Fix from $1,6002025-08-19 MEDIUM 5.3 CVE-2025-51539 EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficient input validation in a scri… Ezged3 3.5.72.27183+ Fix from $1,6002025-08-19 MEDIUM 5.3 CVE-2025-51529 Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows rem… Cookies And Content Security Policy after 2.29 Fix from $1,6002025-08-19 MEDIUM 6.5 CVE-2025-9139 A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plain… Scada Lts No fix yet Fix from $1,6002025-08-19 HIGH 8.5 CVE-2025-32992 Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control. Mitigation only Fix from $1,9502025-08-18 HIGH 7.7 CVE-2025-4962 An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Lunary API, affecting versions up… Patch available Fix from $1,9502025-08-18 MEDIUM 6.3 CVE-2025-9099 A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/… Mitigation only Fix from $1,6002025-08-18 MEDIUM 6.5 CVE-2017-20199 A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an unknown functionality of the co… Buttercup 1.0.1+ Fix from $1,6002025-08-16