Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Youlai Mall MEDIUM 6.5
CVE-2025-14052

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-…

No fix yet
Fix from $1,600 2025-12-05
X Springboot HIGH 7.3
CVE-2025-55948

This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (RBAC) through dual dependency …

No fix yet
Fix from $1,950 2025-12-04
Mall Swarm HIGH 8.1
CVE-2025-14016

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/dele…

Fix: after 1.0.3
Fix from $1,950 2025-12-04
Aquarius Helpertool MEDIUM 5.1
CVE-2025-65842

The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts …

No fix yet
Fix from $1,600 2025-12-03
Grav HIGH 8.8
CVE-2025-66296

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of u…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Orion Ops HIGH 8.8
CVE-2025-13808

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of …

Fix: after 2025-08-01
Fix from $1,950 2025-12-01
Nutzboot CRITICAL 9.8
CVE-2025-13806

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzbo…

Fix: after 2.6.0
Fix from $2,300 2025-12-01
Zentao CRITICAL 9.1
CVE-2025-13787

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the compo…

Fix: 21.7.7+
Fix from $2,300 2025-11-30
Unclassified HIGH 8.8
CVE-2025-45311

Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary operations as root. NOTE: this is …

Mitigation only
Fix from $1,950 2025-11-26
Openbao HIGH 7.2
CVE-2025-64761

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsys…

Fix: 2.4.4+
Fix from $1,950 2025-11-25
Blog Site HIGH 8.8
CVE-2025-13576

A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulat…

Mitigation only
Fix from $1,950 2025-11-24
Unclassified MEDIUM 5.4
CVE-2025-0504

Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user…

No fix yet
Fix from $1,600 2025-11-21
Grafana CRITICAL 9.8
CVE-2025-41115EPSS 17%

SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…

Fix: 12.2.1+
Fix from $2,300 2025-11-21
Mall MEDIUM 6.5
CVE-2025-13443

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Pe…

Fix: after 1.0.3
Fix from $1,600 2025-11-20
Wbce Cms HIGH 8.8
CVE-2025-65094

WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrator…

Fix: 1.6.4+
Fix from $1,950 2025-11-19
Datax Web HIGH 8.8
CVE-2025-13250

A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job…

Fix: after 2.1.2
Fix from $1,950 2025-11-16
Unclassified HIGH 7.8
CVE-2025-13130

A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\ProgramData\Radarr\bin\Radarr.Conso…

Mitigation only
Fix from $1,950 2025-11-13
Unclassified HIGH 7.8
CVE-2025-13131

A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\Sonarr\bin\Sonarr.Console.exe…

Mitigation only
Fix from $1,950 2025-11-13
Mall MEDIUM 5.3
CVE-2025-13117

A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder …

Fix: after 1.0.3
Fix from $1,600 2025-11-13
Mall Swarm MEDIUM 5.3
CVE-2025-13114

A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /cart/update/attr. Such manipul…

Fix: after 1.0.3
Fix from $1,600 2025-11-13
Mall MEDIUM 5.3
CVE-2025-13115

A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the…

Fix: after 1.0.3
Fix from $1,600 2025-11-13
Mall MEDIUM 5.3
CVE-2025-13116

A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserO…

Fix: after 1.0.3
Fix from $1,600 2025-11-13
Unclassified HIGH 8.8
CVE-2025-2843

A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Cu…

Mitigation only
Fix from $1,950 2025-11-12
Unclassified HIGH 7.8
CVE-2024-32009

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privi…

Mitigation only
Fix from $1,950 2025-11-11
Rocketchip MEDIUM 6.5
CVE-2025-63384

A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fai…

Fix: after 1.6
Fix from $1,600 2025-11-10
Unclassified MEDIUM 6.5
CVE-2025-56503

An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate privileges to Administrator v…

Mitigation only
Fix from $1,600 2025-11-10
Unclassified CRITICAL 9.8
CVE-2025-6325

Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Escalation.This issue affects K…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified HIGH 8.8
CVE-2025-62034

Incorrect Privilege Assignment vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.

No fix yet
Fix from $1,950 2025-11-06
Unclassified CRITICAL 9.8
CVE-2025-60243

Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-connector allows Privilege Esc…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.8
CVE-2025-60195

Incorrect Privilege Assignment vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Privilege Escalation.This issue affects Atarim: …

Mitigation only
Fix from $2,300 2025-11-06