Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2025-8226 A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sy… Chancms 3.1.3+ Fix from $2,3002025-07-27 MEDIUM 6.3 CVE-2025-8174 A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the … Voting System No fix yet Fix from $1,6002025-07-26 MEDIUM 6.3 CVE-2025-8171 A vulnerability, which was classified as critical, has been found in code-projects Document Management System 1.0. This issue affects some unknown pr… Document Management System Mitigation only Fix from $1,6002025-07-25 MEDIUM 6.3 CVE-2025-8128 A vulnerability, which was classified as critical, has been found in zhousg letao up to 7d8df0386a65228476290949e0413de48f7fbe98. This issue affects … Mitigation only Fix from $1,6002025-07-25 HIGH 7.7 CVE-2025-6741 Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure m… Devolutions Server 2025.2.5.0+ Fix from $1,9502025-07-22 HIGH 8.8 CVE-2025-7939 A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0. It has been classified as critical. Affected is the function addGoods of t… Jpacookieshop No fix yet Fix from $1,9502025-07-21 CRITICAL 9.8 CVE-2025-44654 In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to syst… E2500 Firmware Mitigation only Fix from $2,3002025-07-21 HIGH 7.3 CVE-2025-7931 A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this issue is some unknown function… Church Donation System No fix yet Fix from $1,9502025-07-21 MEDIUM 5.3 CVE-2025-46118 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, w… Ruckus Unleashed 10.5.1.0.279 / 200.15.6.212.14+ Fix from $1,6002025-07-21 MEDIUM 5.4 CVE-2025-7906 A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi… Ruoyi after 4.8.1 Fix from $1,6002025-07-20 HIGH 7.2 CVE-2025-7898 A vulnerability was found in Codecanyon iDentSoft 2.0. It has been classified as critical. This affects an unknown part of the file /clinica/profile/… Identsoft No fix yet Fix from $1,9502025-07-20 CRITICAL 9.8 CVE-2025-7895 A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of … Moneyprinterturbo after 1.2.6 Fix from $2,3002025-07-20 HIGH 8.8 CVE-2025-7880 A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this issue is some unknown functionality o… Metacrm after 6.4.2 Fix from $1,9502025-07-20 CRITICAL 9.8 CVE-2025-7879 A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnerability is an unknown func… Metacrm after 6.4.2 Fix from $2,3002025-07-20 HIGH 8.8 CVE-2025-7878 A vulnerability, which was classified as critical, was found in Metasoft 美特软件 MetaCRM up to 6.4.2. Affected is an unknown function of the file /c… Metacrm after 6.4.2 Fix from $1,9502025-07-20 CRITICAL 9.8 CVE-2025-7877 A vulnerability, which was classified as critical, has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This issue affects some unknown processin… Metacrm after 6.4.2 Fix from $2,3002025-07-20 CRITICAL 9.1 CVE-2025-7874 A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue is some unknown function… Metacrm after 6.4.2 Fix from $2,3002025-07-20 MEDIUM 5.4 CVE-2025-7864 A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main… Jeesite 5.12.1+ Fix from $1,6002025-07-20 MEDIUM 6.5 CVE-2025-52166 Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate privileges to Administrator … Mitigation only Fix from $1,6002025-07-18 MEDIUM 6.5 CVE-2025-52168 Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers… Mitigation only Fix from $1,6002025-07-18 MEDIUM 6.5 CVE-2025-45157 Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users. Splashin No fix yet Fix from $1,6002025-07-18 HIGH 8.8 CVE-2025-7755 A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of t… Online Ordering System No fix yet Fix from $1,9502025-07-17 HIGH 8.2 CVE-2025-53028 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas… Vm Virtualbox Mitigation only Fix from $1,9502025-07-15 MEDIUM 6.1 CVE-2025-50107 Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Request handling). Supported versions that are affec… Universal Work Queue after 12.2.14 Fix from $1,6002025-07-15 MEDIUM 5.4 CVE-2025-50108 Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Workspace). The supported version that is affected … Hyperion Financial Reporting Patch available Fix from $1,6002025-07-15 HIGH 8.1 CVE-2025-50105 Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). Supported versions th… Universal Work Queue after 12.2.14 Fix from $1,9502025-07-15 MEDIUM 5.3 CVE-2025-50070 Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 23.4-23.8. Difficult to exploit vulnerabilit… Database Server after 23.8 Fix from $1,6002025-07-15 MEDIUM 6.4 CVE-2025-50071 Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affect… Applications Framework after 12.2.14 Fix from $1,6002025-07-15 HIGH 8.6 CVE-2025-50059 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Su… Jre Mitigation only Fix from $1,9502025-07-15 HIGH 8.1 CVE-2025-50060 Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.6.0.0.0, 8.… Bi Publisher Patch available Fix from $1,9502025-07-15