Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2025-50861 The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without auth… Mitigation only Fix from $1,6002025-08-14 MEDIUM 5.3 CVE-2025-20219 A vulnerability in the implementation of access control rules for loopback interfaces in Cisco Secure Firewall Adaptive Security Appliance (ASA) Soft… Mitigation only Fix from $1,6002025-08-14 HIGH 8.8 CVE-2025-8965 A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/… Litemall after 1.8.0 Fix from $1,9502025-08-14 MEDIUM 5.3 CVE-2025-48861 A vulnerability in the Task API endpoint of the ctrlX OS setup mechanism allowed a remote, unauthenticated attacker to access and extract internal ap… Mitigation only Fix from $1,6002025-08-14 HIGH 8.0 CVE-2025-48860 A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) attacker to gain remote access t… Mitigation only Fix from $1,9502025-08-14 HIGH 7.1 CVE-2025-55196 External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15.0 to before 0.19.2, a vulner… Patch available Fix from $1,9502025-08-13 MEDIUM 6.8 CVE-2025-8762 A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The man… Mitigation only Fix from $1,6002025-08-13 HIGH 7.8 CVE-2025-53729 Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. Azure File Sync 18.3.0.0 / 19.2.0.0+ Fix from $1,9502025-08-12 MEDIUM 5.5 CVE-2025-49707 Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. Ecesv6 Series Azure Vm Firmware No fix yet Fix from $1,6002025-08-12 HIGH 8.8 CVE-2025-24999 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. Sql Server 2016 13.0.6465.1 / 13.0.7060.1+ Fix from $1,9502025-08-12 MEDIUM 5.8 CVE-2025-24840 Improper access control for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an unauthenticated … Mitigation only Fix from $1,6002025-08-12 MEDIUM 6.5 CVE-2025-24323 Improper access control in some firmware package and LED mode toggle tool for some Intel(R) PCIe Switch software before version MR4_1.0b1 may allow a… Mitigation only Fix from $1,6002025-08-12 MEDIUM 6.7 CVE-2025-20099 Improper access control for some Intel(R) Rapid Storage Technology installation software may allow an authenticated user to potentially enable escala… Mitigation only Fix from $1,6002025-08-12 HIGH 8.5 CVE-2025-55012 Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by … Mitigation only Fix from $1,9502025-08-11 HIGH 8.8 CVE-2025-8859 A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/… Eblog Site No fix yet Fix from $1,9502025-08-11 MEDIUM 6.1 CVE-2025-8841 A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-b… Microservices Platform after 6.0.0 Fix from $1,6002025-08-11 MEDIUM 6.1 CVE-2025-8798 A vulnerability was found in oitcode samarium up to 0.9.6. It has been classified as critical. Affected is an unknown function of the file /dashboard… Samarium after 0.9.6 Fix from $1,6002025-08-10 CRITICAL 9.9 CVE-2025-8795 A vulnerability, which was classified as critical, was found in LitmusChaos Litmus up to 3.19.0. This affects an unknown part of the file /auth/login… Litmus after 3.19.0 Fix from $2,3002025-08-10 CRITICAL 9.8 CVE-2025-8775 A vulnerability was found in Qiyuesuo Eelectronic Signature Platform up to 4.34 and classified as critical. Affected by this issue is the function ex… Electronic Signature after 4.34 Fix from $2,3002025-08-09 MEDIUM 5.4 CVE-2025-8764 A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upl… Litemall after 1.8.0 Fix from $1,6002025-08-09 MEDIUM 5.3 CVE-2025-8738 A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code o… Mitigation only Fix from $1,6002025-08-08 MEDIUM 6.5 CVE-2024-42048 OpenOrange Business Framework version 1.15.5 installs to a directory with overly permissive access control, allowing all authenticated users to write… Mitigation only Fix from $1,6002025-08-07 MEDIUM 5.3 CVE-2025-54786 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken au… Suitecrm Mitigation only Fix from $1,6002025-08-07 MEDIUM 6.5 CVE-2025-51054 Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior … Vedo Suite No fix yet Fix from $1,6002025-08-06 MEDIUM 5.3 CVE-2024-55402 4C Strategies Exonaut before v22.4 was discovered to contain an access control issue. Exonaut 21.6.2.1-1 / 22.4+ Fix from $1,6002025-08-06 CRITICAL 9.8 CVE-2025-30127 An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video r… Mitigation only Fix from $2,3002025-08-06 HIGH 7.5 CVE-2025-51532 Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Database Monitor via a crafted requ… Sage Dpw 2025_06_000+ Fix from $1,9502025-08-06 MEDIUM 6.5 CVE-2025-46391 CWE-284: Improper Access Control No fix yet Fix from $1,6002025-08-06 HIGH 7.8 CVE-2025-27062 Memory corruption while handling client exceptions, allowing unauthorized channel access. 315 5g Iot Modem Firmware No fix yet Fix from $1,9502025-08-06 MEDIUM 6.5 CVE-2025-51627 Incorrect access control in CaricaVerbale in Agenzia Impresa Eccobook v2.81.1 allows authenticated attackers with low-level access to escalate privil… No fix yet Fix from $1,6002025-08-05