Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Unclassified MEDIUM 6.3
CVE-2025-10247

A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of the component Filter Handler.…

Mitigation only
Fix from $1,600 2025-09-11
Unclassified MEDIUM 5.4
CVE-2025-10209

A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Ha…

Mitigation only
Fix from $1,600 2025-09-10
Platform MEDIUM 6.3
CVE-2025-10086

A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the c…

No fix yet
Fix from $1,600 2025-09-08
I Educar MEDIUM 6.3
CVE-2025-10071

A vulnerability has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /cancelar-enturmacao-em-lote/. …

Fix: after 2.10.0
Fix from $1,600 2025-09-07
I Educar MEDIUM 6.3
CVE-2025-10072

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/…

Fix: after 2.10.0
Fix from $1,600 2025-09-07
I Educar MEDIUM 6.3
CVE-2025-10070

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /enturmacao-em-lote/. This manipulation causes impr…

Fix: after 2.10.0
Fix from $1,600 2025-09-07
Unclassified CRITICAL 9.8
CVE-2025-49401

Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue affects smart SEO: from n/a thr…

Mitigation only
Fix from $2,300 2025-09-05
I Educar MEDIUM 6.3
CVE-2025-10013

A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao-para-o-seb. Performing manip…

Fix: after 2.10.0
Fix from $1,600 2025-09-05
Unclassified MEDIUM 5.5
CVE-2025-58841

Incorrect Privilege Assignment vulnerability in John Luetke Media Author media-author allows Privilege Escalation.This issue affects Media Author: fr…

Mitigation only
Fix from $1,600 2025-09-05
Unclassified MEDIUM 5.4
CVE-2025-9937

A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulat…

Mitigation only
Fix from $1,600 2025-09-04
Realhomes CRITICAL 9.8
CVE-2024-32444

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a …

Fix: 4.3.7+
Fix from $2,300 2025-09-03
I Educar HIGH 8.8
CVE-2025-9760

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Mat…

Fix: after 2.10.0
Fix from $1,950 2025-09-01
I Educar HIGH 8.8
CVE-2025-9687

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoA…

Fix: after 2.10
Fix from $1,950 2025-08-30
I Educar HIGH 8.8
CVE-2025-9609

A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulati…

Fix: after 2.10
Fix from $1,950 2025-08-29
Mybox HIGH 7.7
CVE-2025-58323

NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files …

Fix: 3.0.8.133+
Fix from $1,950 2025-08-29
Rockoa MEDIUM 6.5
CVE-2025-9602

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation result…

Fix: after 2.6.9
Fix from $1,600 2025-08-29
Unclassified CRITICAL 9.8
CVE-2025-49388EPSS 5%

Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Escalation.This issue affects Mir…

Mitigation only
Fix from $2,300 2025-08-28
Mybox HIGH 7.8
CVE-2025-58322

NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs du…

Fix: 3.0.8.133+
Fix from $1,950 2025-08-28
Unclassified HIGH 7.8
CVE-2025-57797

Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6.5L61. If this vulnerability is exploited, an …

Mitigation only
Fix from $1,950 2025-08-27
Unclassified MEDIUM 5.3
CVE-2025-50691

MCSManager 10.5.3 daemon process runs as a root account by default, and its sensitive data (including tokens and terminal content) is stored in the d…

Patch available
Fix from $1,600 2025-08-22
Unclassified HIGH 8.8
CVE-2025-54735

Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This issue affects CubeWP: from n/a…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified CRITICAL 9.9
CVE-2025-54049

Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom …

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 9.8
CVE-2025-53580

Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified CRITICAL 9.8
CVE-2025-49422

Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.This issue affects Support Tic…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified HIGH 8.8
CVE-2025-48164

Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash suredash allows Privilege Escalation.This issue affects SureDash: from n/a …

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 8.8
CVE-2025-48165

Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue affects DELUCKS SEO: from n/a …

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 8.8
CVE-2025-48142

Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify bookify allows Privilege Escalation.This issue affects Bookify: from n/a through <…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified MEDIUM 6.3
CVE-2025-9151

A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the function updateJsonValueByName of …

No fix yet
Fix from $1,600 2025-08-19
Unclassified MEDIUM 6.1
CVE-2025-5417

An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cl…

Mitigation only
Fix from $1,600 2025-08-19
Buttercup MEDIUM 6.5
CVE-2017-20199

A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an unknown functionality of the co…

Fix: 1.0.1+
Fix from $1,600 2025-08-16