Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Cms MEDIUM 6.3
CVE-2025-5428

A vulnerability classified as critical has been found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/log-viewer of th…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5424

A vulnerability was found in juzaweb CMS up to 3.4.2 and classified as critical. This issue affects some unknown processing of the file /admin-cp/med…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5425

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as critical. Affected is an unknown function of the file /admin-cp/theme…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5426

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5423

A vulnerability has been found in juzaweb CMS up to 3.4.2 and classified as critical. This vulnerability affects unknown code of the file /admin-cp/s…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Cms MEDIUM 6.3
CVE-2025-5421

A vulnerability, which was classified as critical, has been found in juzaweb CMS up to 3.4.2. Affected by this issue is some unknown functionality of…

Fix: after 3.4.2
Fix from $1,600 2025-06-02
Mist CRITICAL 9.8
CVE-2025-5409

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the fi…

Fix: 4.7.2+
Fix from $2,300 2025-06-01
Jeewms CRITICAL 9.8
CVE-2025-5389

A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many…

Fix: after 2025-05-04
Fix from $2,300 2025-05-31
Jeewms CRITICAL 9.8
CVE-2025-5390

A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemControll…

Fix: after 2025-05-04
Fix from $2,300 2025-05-31
Jeewms CRITICAL 9.8
CVE-2025-5387

A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.d…

Fix: after 2025-05-04
Fix from $2,300 2025-05-31
Devolutions Server MEDIUM 6.5
CVE-2025-4493

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups …

Fix: after 2025.1.7.0
Fix from $1,600 2025-05-28
Pypickle MEDIUM 5.5
CVE-2025-5175

A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the function Save of the file pypickle/p…

Fix: 2.0.0+
Fix from $1,600 2025-05-26
Warehouse Management System MEDIUM 5.3
CVE-2025-5163

A vulnerability, which was classified as problematic, was found in yangshare 技术杨工 warehouseManager 仓库管理系统 1.0. This affects an unknown part…

No fix yet
Fix from $1,600 2025-05-26
Unclassified MEDIUM 6.8
CVE-2025-48741

A Broken Access Control vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, and 5.4.0 before 5.4.10 allows remote, authenti…

Mitigation only
Fix from $1,600 2025-05-23
Unclassified HIGH 8.8
CVE-2025-47631

Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This issue affects Hospital Manageme…

Mitigation only
Fix from $1,950 2025-05-23
Eventin CRITICAL 9.8
CVE-2025-47539EPSS 33%

Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a …

Fix: 4.0.27+
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-39489

Incorrect Privilege Assignment vulnerability in pebas CouponXL couponxl allows Privilege Escalation.This issue affects CouponXL: from n/a through <= …

Mitigation only
Fix from $2,300 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-31918

Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.…

Mitigation only
Fix from $2,300 2025-05-23
Unclassified MEDIUM 6.4
CVE-2025-48695

An issue was discovered in CyberDAVA before 1.1.20. A privilege escalation vulnerability allows a low-privileged user to escalate their privilege by …

Mitigation only
Fix from $1,600 2025-05-23
Unclassified MEDIUM 6.8
CVE-2025-4692

Actors can use a maliciously crafted JavaScript object notation (JSON) web token (JWT) to perform privilege escalation by submitting the malicious JW…

Mitigation only
Fix from $1,600 2025-05-23
Containerd HIGH 7.5
CVE-2025-47291

containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 an…

Fix: 2.0.5+
Fix from $1,950 2025-05-21
Unclassified HIGH 8.8
CVE-2025-39366

Incorrect Privilege Assignment vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.

No fix yet
Fix from $1,950 2025-05-19
Unclassified HIGH 7.3
CVE-2025-39459

Incorrect Privilege Assignment vulnerability in contempoinc Real Estate 7 realestate-7 allows Privilege Escalation.This issue affects Real Estate 7: …

Mitigation only
Fix from $1,950 2025-05-19
Unclassified HIGH 8.8
CVE-2025-39405

Incorrect Privilege Assignment vulnerability in mojoomla WPAMS apartment-management allows Privilege Escalation.This issue affects WPAMS: from n/a th…

Mitigation only
Fix from $1,950 2025-05-19
Unclassified HIGH 7.1
CVE-2025-0131

An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK used by the Palo Alto Networks GlobalProtect™ app on…

Mitigation only
Fix from $1,950 2025-05-14
Nomad HIGH 7.6
CVE-2025-3744

Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE…

Fix: 1.8.13 / 1.9.9+
Fix from $1,950 2025-05-13
Quay MEDIUM 6.5
CVE-2025-4374

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are gran…

Fix: after 3.14.0
Fix from $1,600 2025-05-06
Maximo Application Suite HIGH 8.8
CVE-2025-2898

IBM Maximo Application Suite 9.0 could allow an attacker with some level of access to elevate their privileges due to a security configuration vulner…

Mitigation only
Fix from $1,950 2025-05-06
A720r Firmware MEDIUM 5.3
CVE-2025-4269

A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/c…

No fix yet
Fix from $1,600 2025-05-05
Devolutions Server MEDIUM 6.3
CVE-2025-3517

Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously co…

Fix: 2025.1.6.0+
Fix from $1,600 2025-05-01