Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Unclassified MEDIUM 6.8
CVE-2025-27028

The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files b…

Mitigation only
Fix from $1,600 2025-07-09
Unclassified HIGH 7.5
CVE-2025-47422

Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation vulnerability. When running as SYSTEM in certain co…

Mitigation only
Fix from $1,950 2025-07-08
Unclassified MEDIUM 6.9
CVE-2025-43001

SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process ext…

Mitigation only
Fix from $1,600 2025-07-08
Unclassified MEDIUM 6.9
CVE-2025-42992

SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit criti…

Mitigation only
Fix from $1,600 2025-07-08
Blackvue Dr590x Firmware HIGH 8.8
CVE-2025-7076

A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical. Affected by this issue is some unknown functionalit…

Fix: after 2025-06-24
Fix from $1,950 2025-07-06
Realhomes CRITICAL 9.8
CVE-2025-49867

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a …

Fix: 4.4.1+
Fix from $2,300 2025-07-04
Unclassified CRITICAL 9.8
CVE-2025-23970

Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation.This issue affects Service Fi…

No fix yet
Fix from $2,300 2025-07-04
G42 Firmware HIGH 7.8
CVE-2025-27021

The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/wri…

Fix: 7.1+
Fix from $1,950 2025-07-02
Unclassified CRITICAL 9.1
CVE-2025-45006

Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential…

Mitigation only
Fix from $2,300 2025-07-01
Incontrol Web HIGH 8.8
CVE-2025-6765

A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 8.6
CVE-2025-52726

Incorrect Privilege Assignment vulnerability in pebas CouponXxL Custom Post Types couponxxl-cpt allows Privilege Escalation.This issue affects Coupon…

Mitigation only
Fix from $1,950 2025-06-27
Cms HIGH 8.8
CVE-2025-6736

A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-…

No fix yet
Fix from $1,950 2025-06-27
Cms HIGH 8.8
CVE-2025-6735

A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the comp…

No fix yet
Fix from $1,950 2025-06-27
Litemall MEDIUM 5.3
CVE-2025-6702

A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment…

No fix yet
Fix from $1,600 2025-06-26
Unclassified HIGH 8.0
CVE-2025-41255

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to …

Mitigation only
Fix from $1,950 2025-06-25
Unclassified MEDIUM 5.3
CVE-2025-6099

A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared as critical. This vulnerabili…

Mitigation only
Fix from $1,600 2025-06-16
Xwiki HIGH 8.0
CVE-2025-49580

XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they co…

Fix: 16.4.7 / 16.10.4+
Fix from $1,950 2025-06-13
Nomad HIGH 8.1
CVE-2025-4922

Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerabilit…

Fix: 1.8.14 / 1.9.10+
Fix from $1,950 2025-06-11
Unclassified CRITICAL 9.8
CVE-2025-48129

Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-pri…

Mitigation only
Fix from $2,300 2025-06-09
Unclassified HIGH 8.8
CVE-2025-47561

Incorrect Privilege Assignment vulnerability in RomanCode MapSVG mapsvg allows Privilege Escalation.This issue affects MapSVG: from n/a through < 8.6…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 8.1
CVE-2025-23974

Incorrect Privilege Assignment vulnerability in ifkooo One-Login one-login allows Privilege Escalation.This issue affects One-Login: from n/a through…

Mitigation only
Fix from $1,950 2025-06-09
Unclassified HIGH 7.1
CVE-2025-5791

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has …

Mitigation only
Fix from $1,950 2025-06-06
Harmonyos HIGH 8.2
CVE-2025-48911

Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availabil…

Mitigation only
Fix from $1,950 2025-06-06
Student Result Management System MEDIUM 6.5
CVE-2025-5649

A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the fil…

No fix yet
Fix from $1,600 2025-06-05
Unifiedtransform MEDIUM 6.5
CVE-2025-46203

An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.

No fix yet
Fix from $1,600 2025-06-04
Unifiedtransform MEDIUM 6.5
CVE-2025-46204

An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.

No fix yet
Fix from $1,600 2025-06-04
Unclassified HIGH 7.3
CVE-2025-5522

A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affe…

Mitigation only
Fix from $1,950 2025-06-03
Shiyi Blog HIGH 7.5
CVE-2025-5511

A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of…

Fix: after 1.2.1
Fix from $1,950 2025-06-03
Cms MEDIUM 6.3
CVE-2025-5429

A vulnerability classified as critical was found in juzaweb CMS up to 3.4.2. This vulnerability affects unknown code of the file /admin-cp/plugin/ins…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5427

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file…

Fix: after 3.4.2
Fix from $1,600 2025-06-02