Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.5 CVE-2025-51060 An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attacker can use DeviceIoControl with the unvalidated parameters 0x9C402440 and 0x9C402444 as I… Cpuz.sys No fix yet Fix from $1,6002025-08-05 MEDIUM 6.5 CVE-2025-43980 An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN. They enable the SSH service by default with the credentials of root/admin. Th… Mitigation only Fix from $1,6002025-08-05 HIGH 7.8 CVE-2025-54871 Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unpriv… Electron Capture 2.20.0+ Fix from $1,9502025-08-05 CRITICAL 9.8 CVE-2025-8526 A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file x… Xboot after 3.3.4 Fix from $2,3002025-08-04 MEDIUM 5.3 CVE-2025-8525 A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring Bo… Xboot after 3.3.4 Fix from $1,6002025-08-04 CRITICAL 9.8 CVE-2025-8504 A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userreg… Kitchen Treasure Mitigation only Fix from $2,3002025-08-03 HIGH 7.3 CVE-2025-23277 NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds … Mitigation only Fix from $1,9502025-08-02 CRITICAL 9.8 CVE-2025-50870 Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The myds GET parameter accepts an e… Mitigation only Fix from $2,3002025-08-01 CRITICAL 9.8 CVE-2025-26062 An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtai… Rx 1500 Firmware Mitigation only Fix from $2,3002025-07-31 HIGH 8.6 CVE-2025-50850 An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and ra… Cs Cart Mitigation only Fix from $1,9502025-07-31 HIGH 7.3 CVE-2025-29556 ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users with the Ad… Mitigation only Fix from $1,9502025-07-31 HIGH 8.0 CVE-2025-52289 A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted reque… Magnusbilling Patch available Fix from $1,9502025-07-31 MEDIUM 5.4 CVE-2025-29557 ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privile… Mitigation only Fix from $1,6002025-07-31 HIGH 7.2 CVE-2025-8379 A vulnerability classified as critical has been found in Campcodes Online Hotel Reservation System 1.0. This affects an unknown part of the file /adm… Online Hotel Reservation System No fix yet Fix from $1,9502025-07-31 CRITICAL 9.8 CVE-2025-8344 A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-ap… Shio after 0.3.8 Fix from $2,3002025-07-31 HIGH 7.8 CVE-2025-50777 The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control vulnerability tha… 2mp Full Hd Smart Wi Fi Cctv Home Security Camera Firmware Mitigation only Fix from $1,9502025-07-30 MEDIUM 6.5 CVE-2025-53111 GLPI is a Free Asset and IT Management Software package. In versions 0.80 through 10.0.18, a lack of permission checks can result in unauthorized acc… Glpi 10.0.19+ Fix from $1,6002025-07-30 HIGH 8.8 CVE-2025-43270 An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.… macOS 13.7.7 / 14.7.7+ Fix from $1,9502025-07-30 MEDIUM 5.5 CVE-2025-43241 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.… macOS 13.7.7 / 14.7.7+ Fix from $1,6002025-07-30 CRITICAL 9.8 CVE-2025-43232 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.… macOS 13.7.7 / 14.7.7+ Fix from $2,3002025-07-30 CRITICAL 9.8 CVE-2025-43233 This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A m… macOS 13.7.7 / 14.7.7+ Fix from $2,3002025-07-30 CRITICAL 9.8 CVE-2025-43192 A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. Account-driven User… macOS 14.7.7 / 15.6+ Fix from $2,3002025-07-30 CRITICAL 9.8 CVE-2025-43194 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be abl… macOS 13.7.7 / 14.7.7+ Fix from $2,3002025-07-30 CRITICAL 9.8 CVE-2025-43198 This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to acces… macOS 14.7.7 / 15.6+ Fix from $2,3002025-07-30 CRITICAL 9.8 CVE-2025-43184 This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.7, macOS Ventu… macOS 13.7.7 / 14.7.7+ Fix from $2,3002025-07-30 HIGH 8.8 CVE-2024-42655 An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wil… Nanomq Patch available Fix from $1,9502025-07-29 CRITICAL 9.8 CVE-2025-27724 A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file… Pacs Server Mitigation only Fix from $2,3002025-07-28 CRITICAL 9.8 CVE-2025-30133 An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD… Fx2 Firmware Mitigation only Fix from $2,3002025-07-28 CRITICAL 9.8 CVE-2025-8256 A vulnerability classified as critical has been found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin… Online Ordering System Mitigation only Fix from $2,3002025-07-28 CRITICAL 9.8 CVE-2025-8255 A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects some unknown processing of the… Exam Form Submission Mitigation only Fix from $2,3002025-07-28