Total
5364 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-66956 | 2026-07-05 | N/A | 9.9 CRITICAL | ||
| Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachments via a computable URL. | |||||
| CVE-2025-65594 | 1 Os4ed | 1 Opensis | 2026-07-05 | N/A | 8.1 HIGH |
| OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users. | |||||
| CVE-2025-63409 | 1 Gcomtw | 2 Gcom Epon 1ge, Gcom Epon 1ge Firmware | 2026-07-05 | N/A | 8.8 HIGH |
| Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials. | |||||
| CVE-2025-61229 | 1 Shirt-pocket | 1 Superduper\! | 2026-07-05 | N/A | 7.8 HIGH |
| An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls. | |||||
| CVE-2025-60306 | 1 Code-projects | 1 Simple Car Rental System | 2026-07-05 | N/A | 9.9 CRITICAL |
| code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations. | |||||
| CVE-2025-60305 | 1 Senior-walter | 1 Online Student Clearance System | 2026-07-05 | N/A | 8.8 HIGH |
| SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations. | |||||
| CVE-2025-57567 | 2026-07-05 | N/A | 9.1 CRITICAL | ||
| A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code via the admin panel, enabling execution of system commands. | |||||
| CVE-2025-57489 | 1 Shirt-pocket | 1 Superduper\! | 2026-07-05 | N/A | 8.1 HIGH |
| Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary. | |||||
| CVE-2025-57197 | 2026-07-05 | N/A | 6.0 MEDIUM | ||
| In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass the current PIN verification check and directly modify the authentication PIN. This allows unauthorized users to change PIN without knowing the original/current PIN. | |||||
| CVE-2025-57130 | 1 Zwiicms | 1 Zwiicms | 2026-07-05 | N/A | 8.3 HIGH |
| An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By sending a specially crafted HTTP request, a low-privilege user can access and modify the profile data of any other user, including administrators. | |||||
| CVE-2025-56274 | 1 Senior-walter | 1 Web-based Pharmacy Product Management System | 2026-07-05 | N/A | 8.1 HIGH |
| SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high privileged (such as admin) sessions and perform sensitive operations such as adding new users. | |||||
| CVE-2025-55373 | 1 Beakon | 1 Beakon | 2026-07-05 | N/A | 5.3 MEDIUM |
| Incorrect access control in Beakon Application before v5.4.3 allows authenticated attackers with low-level privileges to escalate privileges and execute commands with Administrator rights. | |||||
| CVE-2025-55371 | 1 Jishenghua | 1 Jsherp | 2026-07-05 | N/A | 5.3 MEDIUM |
| Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method. | |||||
| CVE-2025-55368 | 1 Jishenghua | 1 Jsherp | 2026-07-05 | N/A | 8.8 HIGH |
| Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account. | |||||
| CVE-2025-55367 | 1 Jishenghua | 1 Jsherp | 2026-07-05 | N/A | 5.3 MEDIUM |
| Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account. | |||||
| CVE-2025-55366 | 1 Jishenghua | 1 Jsherp | 2026-07-05 | N/A | 5.3 MEDIUM |
| Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack. | |||||
| CVE-2025-52168 | 2026-07-05 | N/A | 6.5 MEDIUM | ||
| Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers to access arbitrary files on the system. | |||||
| CVE-2025-52166 | 2026-07-05 | N/A | 6.5 MEDIUM | ||
| Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate privileges to Administrator and access sensitive components and information. | |||||
| CVE-2025-51054 | 1 Vedo Suite Project | 1 Vedo Suite | 2026-07-05 | N/A | 6.5 MEDIUM |
| Vedo Suite 2024.17 is vulnerable to Incorrect Access Control, which allows remote attackers to obtain a valid high privilege JWT token without prior authentication via sending an empty HTTP POST request to the /autologin/ API endpoint. | |||||
| CVE-2025-50850 | 1 Cs-cart | 1 Cs-cart | 2026-07-05 | N/A | 8.6 HIGH |
| An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verification and rate limiting. This allows an attacker to systematically attempt various combinations of usernames and passwords (brute-force attack) to gain unauthorized access to vendor accounts. The absence of any blocking mechanism makes the login endpoint susceptible to automated attacks. | |||||
