Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Jizhicms MEDIUM 5.3
CVE-2025-2639

A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/relea…

Fix: after 1.7
Fix from $1,600 2025-03-23
Jizhicms MEDIUM 5.3
CVE-2025-2638

A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file /user/release.html …

Fix: after 1.7
Fix from $1,600 2025-03-23
Jizhicms MEDIUM 5.3
CVE-2025-2637

A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of…

Fix: after 1.7
Fix from $1,600 2025-03-23
Human Resource Management CRITICAL 9.8
CVE-2025-2589

A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index o…

No fix yet
Fix from $2,300 2025-03-21
Unclassified MEDIUM 5.5
CVE-2025-2557

A vulnerability, which was classified as critical, has been found in Audi UTR Dashcam 2.0. Affected by this issue is some unknown functionality of th…

Mitigation only
Fix from $1,600 2025-03-20
Dir 618 Firmware HIGH 8.8
CVE-2025-2549

A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this vulnerability is an unknown f…

No fix yet
Fix from $1,950 2025-03-20
Dir 618 Firmware HIGH 8.8
CVE-2025-2548

A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an unknown function of the file…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 8.1
CVE-2025-0628

An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs i…

Patch available
Fix from $1,950 2025-03-20
Smartfabric Os10 HIGH 7.8
CVE-2024-49561

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Assignment vulnerability. A low …

Fix: 10.5.4.14 / 10.5.5.13+
Fix from $1,950 2025-03-17
Dir 823g Firmware CRITICAL 9.8
CVE-2025-2360

A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings…

No fix yet
Fix from $2,300 2025-03-17
Dir 823g Firmware CRITICAL 9.8
CVE-2025-2359EPSS 15%

A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNA…

No fix yet
Fix from $2,300 2025-03-17
Unclassified CRITICAL 9.8
CVE-2025-2345

A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. This affects an unknown part. …

Mitigation only
Fix from $2,300 2025-03-16
Springboot Openai Chatgpt CRITICAL 9.1
CVE-2025-2334

A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects the function deleteChat of the …

No fix yet
Fix from $2,300 2025-03-15
Ulisting HIGH 8.8
CVE-2025-1653

The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2…

Fix: after 2.1.7
Fix from $1,950 2025-03-15
Springboot Openai Chatgpt CRITICAL 9.8
CVE-2025-2320

A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this vulnerability is the funct…

No fix yet
Fix from $2,300 2025-03-14
Lovecards CRITICAL 9.8
CVE-2025-2218

A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /…

Fix: after 2.3.2
Fix from $2,300 2025-03-12
F800 Pro Firmware HIGH 8.8
CVE-2025-2121

A vulnerability classified as critical has been found in Thinkware Car Dashcam F800 Pro up to 20250226. Affected is an unknown function of the compon…

No fix yet
Fix from $1,950 2025-03-09
Starsea Mall MEDIUM 5.4
CVE-2025-2089

A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUse…

No fix yet
Fix from $1,600 2025-03-07
Unclassified MEDIUM 6.5
CVE-2025-21092

GMOD Apollo does not have sufficient logical or access checks when updating a user's information. This could result in an attacker being able to esca…

Mitigation only
Fix from $1,600 2025-03-05
Unclassified MEDIUM 5.4
CVE-2024-55570

/api/user/users in the web GUI for the Cubro EXA48200 network packet broker (build 20231025055018) fixed in V5.0R14.5P4-V3.3R1 allows remote authenti…

Mitigation only
Fix from $1,600 2025-03-03
Zz HIGH 8.8
CVE-2025-1847

A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as critical. This issue affects some unknown processing. The manipulation lead…

Fix: after 2024-8
Fix from $1,950 2025-03-03
Unclassified HIGH 7.3
CVE-2025-1815

A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resou…

Mitigation only
Fix from $1,950 2025-03-02
Dhvc Form CRITICAL 9.8
CVE-2024-8420

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allow…

Fix: 2.4.8+
Fix from $2,300 2025-02-28
Unclassified CRITICAL 9.8
CVE-2024-56000

Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/…

Mitigation only
Fix from $2,300 2025-02-18
Unclassified HIGH 7.4
CVE-2025-26523

This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoints handling addition and dele…

Mitigation only
Fix from $1,950 2025-02-14
Yimioa CRITICAL 9.8
CVE-2025-1226

A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/s…

Fix: 2024-07-04+
Fix from $2,300 2025-02-12
Superio CRITICAL 9.8
CVE-2024-12213

The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a us…

Fix: after 1.2.76
Fix from $2,300 2025-02-12
Real Estate 7 CRITICAL 9.8
CVE-2024-13421

The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the…

Fix: 3.5.2+
Fix from $2,300 2025-02-12
Fortios HIGH 7.2
CVE-2024-40591

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.…

Fix: 6.4.16 / 7.0.16+
Fix from $1,950 2025-02-11
Unclassified MEDIUM 5.3
CVE-2025-1078

A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects t…

Mitigation only
Fix from $1,600 2025-02-06