Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 8.8 CVE-2025-6422 A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this vulnerability is an unknown … Online Recruitment Management System No fix yet Fix from $1,9502025-06-21 CRITICAL 9.8 CVE-2025-6266 A vulnerability was detected in Teledyne FLIR AX8 up to 1.46. Affected by this vulnerability is an unknown functionality of the file /upload.php. Per… Flir Ax8 Firmware 1.49.16+ Fix from $2,3002025-06-19 HIGH 7.5 CVE-2025-31698 ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users can use a new setting (proxy.… Traffic Server 9.2.11 / 10.0.6+ Fix from $1,9502025-06-19 CRITICAL 9.8 CVE-2024-45208 The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP … Mitigation only Fix from $2,3002025-06-19 CRITICAL 9.1 CVE-2025-49591 CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, d… Cryptpad 2025.3.0+ Fix from $2,3002025-06-18 HIGH 7.8 CVE-2025-49154 An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwri… Worry Free Business Security 6.7.3954 / 14.0.0.14002+ Fix from $1,9502025-06-17 CRITICAL 9.8 CVE-2025-6161 A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of th… Simple Food Ordering System Mitigation only Fix from $2,3002025-06-17 HIGH 7.8 CVE-2025-27689 Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged attacker with local access coul… Idrac Tools 11.3.0.0+ Fix from $1,9502025-06-12 MEDIUM 5.4 CVE-2025-46889 Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalati… Experience Manager 6.5.23.0 / 2025.5.0+ Fix from $1,6002025-06-10 HIGH 7.8 CVE-2025-47962 Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally. Windows Software Development Kit 10.0.26100.4188+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-33073 KEVEPSS 80% Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. Windows 10 1507 10.0.10240.21034 / 10.0.14393.8148+ Fix from $1,9502025-06-10 HIGH 7.5 CVE-2025-33056 Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network. Windows 10 1507 10.0.10240.21034 / 10.0.14393.8148+ Fix from $1,9502025-06-10 MEDIUM 5.5 CVE-2025-32722 Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21034 / 10.0.14393.8148+ Fix from $1,6002025-06-10 HIGH 7.8 CVE-2025-32714 Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21034 / 10.0.14393.8148+ Fix from $1,9502025-06-10 CRITICAL 9.8 CVE-2024-57190 Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any use… Erxes 1.6.1+ Fix from $2,3002025-06-10 HIGH 8.1 CVE-2025-43586 Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that co… Commerce Mitigation only Fix from $1,9502025-06-10 MEDIUM 5.3 CVE-2025-27206 Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that co… Commerce Mitigation only Fix from $1,6002025-06-10 MEDIUM 6.5 CVE-2025-27207 Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that co… Commerce B2b Mitigation only Fix from $1,6002025-06-10 MEDIUM 6.3 CVE-2025-5873 A vulnerability was detected in eCharge Hardy Barth Salia PLCC up to 2.3.81. Affected by this issue is some unknown functionality of the file /firmwa… Mitigation only Fix from $1,6002025-06-09 HIGH 7.3 CVE-2025-5840 A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of… Client Database Management System No fix yet Fix from $1,9502025-06-07 HIGH 8.8 CVE-2025-5728 A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code … Open Source Clinic Management System No fix yet Fix from $1,9502025-06-06 MEDIUM 6.8 CVE-2025-5382 Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or … Devolutions Server 2025.1.9.0+ Fix from $1,6002025-06-05 MEDIUM 5.0 CVE-2025-3768 Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor … Devolutions Server after 2025.1.10.0 Fix from $1,6002025-06-05 MEDIUM 5.0 CVE-2025-0691 Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permi… Devolutions Server after 2025.1.10.0 Fix from $1,6002025-06-05 MEDIUM 6.5 CVE-2025-5649 A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the fil… Student Result Management System No fix yet Fix from $1,6002025-06-05 HIGH 7.2 CVE-2025-20130 A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, r… Identity Services Engine 3.1.0+ Fix from $1,9502025-06-04 HIGH 8.8 CVE-2025-48999EPSS 8% DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10.… Dataease 2.10.10+ Fix from $1,9502025-06-03 HIGH 7.8 CVE-2024-53010 Memory corruption may occur while attaching VM when the HLOS retains access to VM. Aqt1000 Firmware Mitigation only Fix from $1,9502025-06-03 MEDIUM 5.3 CVE-2025-5436 A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic. This issue affects some unknown processing of the file… Mitigation only Fix from $1,6002025-06-02 MEDIUM 6.3 CVE-2025-5429 A vulnerability classified as critical was found in juzaweb CMS up to 3.4.2. This vulnerability affects unknown code of the file /admin-cp/plugin/ins… Cms after 3.4.2 Fix from $1,6002025-06-02