Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Unclassified HIGH 8.8
CVE-2025-62034

Incorrect Privilege Assignment vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4.

No fix yet
Fix from $1,950 2025-11-06
Unclassified CRITICAL 9.8
CVE-2025-60243

Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-connector allows Privilege Esc…

Mitigation only
Fix from $2,300 2025-11-06
Unclassified CRITICAL 9.8
CVE-2025-60195

Incorrect Privilege Assignment vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Privilege Escalation.This issue affects Atarim: …

Mitigation only
Fix from $2,300 2025-11-06
Unclassified HIGH 8.8
CVE-2025-49900

Incorrect Privilege Assignment vulnerability in bPlugins Advanced scrollbar advanced-scrollbar allows Privilege Escalation.This issue affects Advance…

Mitigation only
Fix from $1,950 2025-11-06
Log Server HIGH 7.8
CVE-2024-58273

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands …

Fix: 2024+
Fix from $1,950 2025-10-30
Unclassified MEDIUM 5.0
CVE-2025-12103

A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to get,…

Mitigation only
Fix from $1,600 2025-10-28
Qradar Security Information And Event Manager HIGH 7.8
CVE-2025-36007

IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an …

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 8.8
CVE-2025-62007

Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback:…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified CRITICAL 9.8
CVE-2025-60220

Incorrect Privilege Assignment vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects CouponXxL: from n/a through …

Mitigation only
Fix from $2,300 2025-10-22
Unclassified HIGH 8.8
CVE-2025-60222

Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This is…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 8.8
CVE-2025-60211

Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 8.8
CVE-2025-59580

Incorrect Privilege Assignment vulnerability in GoodLayers Goodlayers Core goodlayers-core allows Privilege Escalation.This issue affects Goodlayers …

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 8.8
CVE-2025-53428

Incorrect Privilege Assignment vulnerability in N-Media Simple User Registration wp-registration allows Privilege Escalation.This issue affects Simpl…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.2
CVE-2025-53425

Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.2
CVE-2025-49924

Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue aff…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 8.8
CVE-2025-48082

Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Pro…

Mitigation only
Fix from $1,950 2025-10-22
Restaurant Brands International Assistant CRITICAL 9.9
CVE-2025-62645

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with adminis…

Fix: after 2025-09-06
Fix from $2,300 2025-10-17
Teedy HIGH 8.1
CVE-2025-11853

A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Exe…

Fix: after 1.11
Fix from $1,950 2025-10-16
Unclassified HIGH 8.5
CVE-2025-10577

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might …

Mitigation only
Fix from $1,950 2025-10-15
Unclassified HIGH 8.5
CVE-2025-10576

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might …

Mitigation only
Fix from $1,950 2025-10-15
Unclassified MEDIUM 6.5
CVE-2025-10038

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_…

Mitigation only
Fix from $1,600 2025-10-15
Furbo Mini Firmware HIGH 8.1
CVE-2025-11646

A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the component GATT Service. The manipula…

Fix: after 074
Fix from $1,950 2025-10-12
Furbo Mini Firmware MEDIUM 6.4
CVE-2025-11641

A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This…

Fix: after 074
Fix from $1,600 2025-10-12
I Educar HIGH 8.8
CVE-2025-11554

A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/…

Fix: after 2.9.10
Fix from $1,950 2025-10-09
Data Domain Operating System HIGH 7.8
CVE-2025-43914

Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0,…

Fix: 7.10.1.70 / 8.3.1.10+
Fix from $1,950 2025-10-07
Learning MEDIUM 5.0
CVE-2025-11281

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished C…

No fix yet
Fix from $1,600 2025-10-05
Unclassified MEDIUM 5.4
CVE-2025-11272

A vulnerability has been found in SeriaWei ZKEACMS up to 4.3. This affects the function Delete of the file src/ZKEACMS.Redirection/Controllers/UrlRed…

Mitigation only
Fix from $1,600 2025-10-04
Unclassified CRITICAL 9.9
CVE-2025-10725

A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist …

Patch available
Fix from $2,300 2025-09-30
I Educar HIGH 8.8
CVE-2025-11050

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lea…

Fix: after 2.10.0
Fix from $1,950 2025-09-27
I Educar HIGH 8.8
CVE-2025-11049

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /unificacao-aluno. P…

Fix: after 2.10.0
Fix from $1,950 2025-09-27