Total
9949 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-41342 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_user' in '/backend/api/buscarUsuarioId.php'. | |||||
| CVE-2025-41341 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'seguro' in '/backend/api/buscarUsuarioByDenuncia.php'. | |||||
| CVE-2025-41340 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_tp_denuncia' and 'id_sociedad' in '/backend/api/buscarTipoDenunciabyId.php'. | |||||
| CVE-2025-41339 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/api/buscarTipoDenuncia.php'. | |||||
| CVE-2025-41338 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarTestigoByIdDenunciaUsuario.php'. | |||||
| CVE-2025-41337 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarSSOParametros.php'. | |||||
| CVE-2025-41336 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros.php'. | |||||
| CVE-2025-41335 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'. | |||||
| CVE-2025-41231 | 1 Vmware | 1 Cloud Foundation | 2026-06-17 | N/A | 7.3 HIGH |
| VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information. | |||||
| CVE-2025-41114 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'. | |||||
| CVE-2025-41113 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarDenunciaByPin.php'. | |||||
| CVE-2025-41112 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros2.php'. | |||||
| CVE-2025-41111 | 1 Canaldenuncia | 1 Canaldenuncia.app | 2026-06-17 | N/A | 7.5 HIGH |
| A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarComentariosByDenuncia.php'. | |||||
| CVE-2025-41017 | 2026-06-17 | N/A | N/A | ||
| Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve perspective parameters from security camera settings by accessing “/cameras/<CAMERA_ID>/perspective”. | |||||
| CVE-2025-41016 | 2026-06-17 | N/A | N/A | ||
| Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images and videos related to alarm events through access to “/alarms/<ALARM_ID>/<MEDIA>”, where the “MEDIA” parameter can take the value of “snapshot” or “video.mp4”. These media files contain images recorded by security cameras in response to triggered alerts. | |||||
| CVE-2025-41012 | 1 Tcman | 1 Gim | 2026-06-17 | N/A | 5.3 MEDIUM |
| Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by using the 'pda:userId' and 'pda:newPassword' parameters with 'soapaction UnlockUser’ in '/WS/PDAWebService.asmx'. | |||||
| CVE-2025-40837 | 1 Ericsson | 2 Indoor Connect 8855, Indoor Connect 8855 Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| Ericsson Indoor Connect 8855 contains a missing authorization vulnerability which if exploited can allow access to the system as a user with higher privileges than intended. | |||||
| CVE-2025-40673 | 2026-06-17 | N/A | N/A | ||
| A Missing Authorization vulnerability has been found in DinoRANK. This vulnerability allows an attacker to access invoices of any user via accessing endpoint '/facturas/YYYY-MM/SDRYYMM-XXXXX.pdf' because there is no access control. The pdf filename can be obtained via OSINT, insecure network traffic or brute force. | |||||
| CVE-2025-40667 | 1 Tcman | 1 Gim | 2026-06-17 | N/A | 6.5 MEDIUM |
| Missing authorization vulnerability in TCMAN's GIM v11. This allows an authenticated attacker to access any functionality of the application even when they are not available through the user interface. To exploit the vulnerability the attacker must modify the HTTP code of the response from ‘302 Found’ to ‘200 OK’, as well as the hidden fields hdnReadOnly and hdnUserLogin. | |||||
| CVE-2025-40602 | 1 Sonicwall | 9 Sma6200, Sma6200 Firmware, Sma6210 and 6 more | 2026-06-17 | N/A | 6.6 MEDIUM |
| A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). | |||||
