Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
HIGH 8.8 CVE-2025-49900 Incorrect Privilege Assignment vulnerability in bPlugins Advanced scrollbar advanced-scrollbar allows Privilege Escalation.This issue affects Advance… Mitigation only Fix from $1,9502025-11-06 HIGH 7.8 CVE-2024-58273 Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands … Log Server 2024+ Fix from $1,9502025-10-30 MEDIUM 5.0 CVE-2025-12103 A flaw was found in Red Hat Openshift AI Service. The TrustyAI component is granting all service accounts and users on a cluster permissions to get,… Mitigation only Fix from $1,6002025-10-28 HIGH 7.8 CVE-2025-36007 IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 13 Independent Fix 02 is vulnerable to privilege escalation due to improper privilege assignment to an … Qradar Security Information And Event Manager Mitigation only Fix from $1,9502025-10-27 HIGH 8.8 CVE-2025-62007 Incorrect Privilege Assignment vulnerability in bPlugins Voice Feedback voice-feedback allows Privilege Escalation.This issue affects Voice Feedback:… Mitigation only Fix from $1,9502025-10-22 CRITICAL 9.8 CVE-2025-60220 Incorrect Privilege Assignment vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affects CouponXxL: from n/a through … Mitigation only Fix from $2,3002025-10-22 HIGH 8.8 CVE-2025-60222 Incorrect Privilege Assignment vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Privilege Escalation.This is… Mitigation only Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-60211 Incorrect Privilege Assignment vulnerability in extendons WooCommerce Registration Fields Plugin - Custom Signup Fields extendons-registration-fields… Mitigation only Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-59580 Incorrect Privilege Assignment vulnerability in GoodLayers Goodlayers Core goodlayers-core allows Privilege Escalation.This issue affects Goodlayers … Mitigation only Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-53428 Incorrect Privilege Assignment vulnerability in N-Media Simple User Registration wp-registration allows Privilege Escalation.This issue affects Simpl… Mitigation only Fix from $1,9502025-10-22 HIGH 7.2 CVE-2025-53425 Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <… Mitigation only Fix from $1,9502025-10-22 HIGH 7.2 CVE-2025-49924 Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue aff… Mitigation only Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-48082 Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Pro… Mitigation only Fix from $1,9502025-10-22 CRITICAL 9.9 CVE-2025-62645 The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with adminis… Restaurant Brands International Assistant after 2025-09-06 Fix from $2,3002025-10-17 HIGH 8.1 CVE-2025-11853 A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Exe… Teedy after 1.11 Fix from $1,9502025-10-16 HIGH 8.5 CVE-2025-10577 Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might … Mitigation only Fix from $1,9502025-10-15 HIGH 8.5 CVE-2025-10576 Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might … Mitigation only Fix from $1,9502025-10-15 MEDIUM 6.5 CVE-2025-10038 The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_… Mitigation only Fix from $1,6002025-10-15 HIGH 8.1 CVE-2025-11646 A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the component GATT Service. The manipula… Furbo Mini Firmware after 074 Fix from $1,9502025-10-12 MEDIUM 6.4 CVE-2025-11641 A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This… Furbo Mini Firmware after 074 Fix from $1,6002025-10-12 HIGH 8.8 CVE-2025-11554 A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/… I Educar after 2.9.10 Fix from $1,9502025-10-09 HIGH 7.8 CVE-2025-43914 Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0,… Data Domain Operating System 7.10.1.70 / 8.3.1.10+ Fix from $1,9502025-10-07 MEDIUM 5.0 CVE-2025-11281 A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished C… Learning No fix yet Fix from $1,6002025-10-05 MEDIUM 5.4 CVE-2025-11272 A vulnerability has been found in SeriaWei ZKEACMS up to 4.3. This affects the function Delete of the file src/ZKEACMS.Redirection/Controllers/UrlRed… Mitigation only Fix from $1,6002025-10-04 CRITICAL 9.9 CVE-2025-10725 A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist … Patch available Fix from $2,3002025-09-30 HIGH 8.8 CVE-2025-11050 A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lea… I Educar after 2.10.0 Fix from $1,9502025-09-27 HIGH 8.8 CVE-2025-11049 A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /unificacao-aluno. P… I Educar after 2.10.0 Fix from $1,9502025-09-27 HIGH 8.1 CVE-2025-59945 SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated and unprivileged (non-admin) … Sysreptor 2025.83+ Fix from $1,9502025-09-27 HIGH 8.8 CVE-2025-11048 A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file … I Educar after 2.10.0 Fix from $1,9502025-09-26 HIGH 8.8 CVE-2025-11047 A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of… I Educar after 2.10.0 Fix from $1,9502025-09-26