Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Supportassist For Business Pcs HIGH 7.8
CVE-2025-36612

SupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker wit…

Fix: 4.9.0+
Fix from $1,950 2025-08-14
Supportassist For Business Pcs HIGH 7.8
CVE-2025-36613

SupportAssist for Home PCs versions 4.6.3 and prior and SupportAssist for Business PCs versions 4.5.3 and prior, contain(s) an Incorrect Privilege As…

Fix: 4.8.2.38851 / 4.9.0+
Fix from $1,950 2025-08-14
Supportassist For Home Pcs HIGH 7.8
CVE-2025-38738

SupportAssist for Home PCs Installer exe version(s) 4.8.2.29006 and prior, contain(s) an Incorrect Privilege Assignment vulnerability in the Installe…

Fix: 4.8.2.38851+
Fix from $1,950 2025-08-14
Unclassified HIGH 7.2
CVE-2025-54697

Incorrect Privilege Assignment vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Privilege Esca…

Mitigation only
Fix from $1,950 2025-08-14
GitLab MEDIUM 5.5
CVE-2024-12303

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under ce…

Fix: 18.0.6 / 18.1.4+
Fix from $1,600 2025-08-13
Fortios HIGH 7.2
CVE-2025-53744

An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versio…

Fix: 7.4.8 / 7.6.3+
Fix from $1,950 2025-08-12
Sap Basis MEDIUM 5.4
CVE-2025-42936

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this …

Patch available
Fix from $1,600 2025-08-12
Jsherp MEDIUM 5.4
CVE-2025-8840

A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoi…

No fix yet
Fix from $1,600 2025-08-11
Jsherp HIGH 8.8
CVE-2025-8839

A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endp…

No fix yet
Fix from $1,950 2025-08-11
Litmus HIGH 8.8
CVE-2025-8797

A vulnerability was found in LitmusChaos Litmus up to 3.19.0 and classified as critical. This issue affects some unknown processing of the component …

Fix: after 3.19.0
Fix from $1,950 2025-08-10
Litmus CRITICAL 9.9
CVE-2025-8795

A vulnerability, which was classified as critical, was found in LitmusChaos Litmus up to 3.19.0. This affects an unknown part of the file /auth/login…

Fix: after 3.19.0
Fix from $2,300 2025-08-10
Litmus MEDIUM 6.3
CVE-2025-8791

A vulnerability was found in LitmusChaos Litmus up to 3.19.0. It has been rated as critical. This issue affects some unknown processing of the file /…

Fix: after 3.19.0
Fix from $1,600 2025-08-10
Unclassified HIGH 7.0
CVE-2025-8758

A vulnerability was found in TRENDnet TEW-822DRE FW103B02. It has been classified as problematic. This affects an unknown part of the component vsftp…

No fix yet
Fix from $1,950 2025-08-09
Tduck Platform HIGH 8.8
CVE-2025-8756

A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preH…

Fix: after 5.1
Fix from $1,950 2025-08-09
Unclassified HIGH 7.0
CVE-2025-8757

A vulnerability was found in TRENDnet TV-IP110WN 1.2.2 and classified as problematic. Affected by this issue is some unknown functionality of the fil…

No fix yet
Fix from $1,950 2025-08-09
Pybbs MEDIUM 5.3
CVE-2025-8547

A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email …

Fix: after 6.0.0
Fix from $1,600 2025-08-05
Vault HIGH 7.2
CVE-2025-5999

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s token privile…

Fix: 1.16.22 / 1.18.11+
Fix from $1,950 2025-08-01
macOS MEDIUM 5.1
CVE-2025-43260

This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to hijack …

Fix: 14.7.7 / 15.6+
Fix from $1,600 2025-07-30
Unclassified MEDIUM 6.8
CVE-2025-2179

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on Linux devices enables a locally authenticated non adm…

Mitigation only
Fix from $1,600 2025-07-29
Vaelsys CRITICAL 9.8
CVE-2025-8261

A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the componen…

Mitigation only
Fix from $2,300 2025-07-28
N600r Firmware HIGH 7.2
CVE-2025-8181

A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unknown part of the file vsftpd.co…

No fix yet
Fix from $1,950 2025-07-26
Unclassified MEDIUM 6.5
CVE-2025-31513

An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to administrator privileges via the IsAdminApprover parameter in a …

Mitigation only
Fix from $1,600 2025-07-22
Jsherp HIGH 8.1
CVE-2025-7947

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component …

Fix: after 3.5
Fix from $1,950 2025-07-22
A7100ru Firmware CRITICAL 9.8
CVE-2025-44655

In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized acce…

Mitigation only
Fix from $2,300 2025-07-21
Unclassified CRITICAL 9.8
CVE-2025-52836

Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Privilege Escalation.This issue…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified CRITICAL 10.0
CVE-2025-34112

An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances…

Mitigation only
Fix from $2,300 2025-07-15
Unclassified HIGH 7.3
CVE-2025-7576

A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16 and classified as critical. Affected by this issue is some unkn…

No fix yet
Fix from $1,950 2025-07-14
Unclassified MEDIUM 6.3
CVE-2025-7552

A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the fi…

Mitigation only
Fix from $1,600 2025-07-14
Unclassified MEDIUM 6.3
CVE-2025-0139

An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privil…

Mitigation only
Fix from $1,600 2025-07-09
Unclassified MEDIUM 6.8
CVE-2025-0140

An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a locally authenticated non adm…

Mitigation only
Fix from $1,600 2025-07-09