Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
MEDIUM 6.3 CVE-2025-10247 A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of the component Filter Handler.… Mitigation only Fix from $1,6002025-09-11 MEDIUM 5.4 CVE-2025-10209 A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Ha… Mitigation only Fix from $1,6002025-09-10 MEDIUM 6.3 CVE-2025-10086 A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the c… Platform No fix yet Fix from $1,6002025-09-08 MEDIUM 6.3 CVE-2025-10071 A vulnerability has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /cancelar-enturmacao-em-lote/. … I Educar after 2.10.0 Fix from $1,6002025-09-07 MEDIUM 6.3 CVE-2025-10072 A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/… I Educar after 2.10.0 Fix from $1,6002025-09-07 MEDIUM 6.3 CVE-2025-10070 A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /enturmacao-em-lote/. This manipulation causes impr… I Educar after 2.10.0 Fix from $1,6002025-09-07 CRITICAL 9.8 CVE-2025-49401 Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue affects smart SEO: from n/a thr… Mitigation only Fix from $2,3002025-09-05 MEDIUM 6.3 CVE-2025-10013 A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /exportacao-para-o-seb. Performing manip… I Educar after 2.10.0 Fix from $1,6002025-09-05 MEDIUM 5.5 CVE-2025-58841 Incorrect Privilege Assignment vulnerability in John Luetke Media Author media-author allows Privilege Escalation.This issue affects Media Author: fr… Mitigation only Fix from $1,6002025-09-05 MEDIUM 5.4 CVE-2025-9937 A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulat… Mitigation only Fix from $1,6002025-09-04 CRITICAL 9.8 CVE-2024-32444 Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a … Realhomes 4.3.7+ Fix from $2,3002025-09-03 HIGH 8.8 CVE-2025-9760 A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Mat… I Educar after 2.10.0 Fix from $1,9502025-09-01 HIGH 8.8 CVE-2025-9687 A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoA… I Educar after 2.10 Fix from $1,9502025-08-30 HIGH 8.8 CVE-2025-9609 A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulati… I Educar after 2.10 Fix from $1,9502025-08-29 HIGH 7.7 CVE-2025-58323 NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files … Mybox 3.0.8.133+ Fix from $1,9502025-08-29 MEDIUM 6.5 CVE-2025-9602 A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation result… Rockoa after 2.6.9 Fix from $1,6002025-08-29 CRITICAL 9.8 CVE-2025-49388EPSS 5% Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Privilege Escalation.This issue affects Mir… Mitigation only Fix from $2,3002025-08-28 HIGH 7.8 CVE-2025-58322 NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by invoking arbitrary DLLs du… Mybox 3.0.8.133+ Fix from $1,9502025-08-28 HIGH 7.8 CVE-2025-57797 Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6.5L61. If this vulnerability is exploited, an … Mitigation only Fix from $1,9502025-08-27 MEDIUM 5.3 CVE-2025-50691 MCSManager 10.5.3 daemon process runs as a root account by default, and its sensitive data (including tokens and terminal content) is stored in the d… Patch available Fix from $1,6002025-08-22 HIGH 8.8 CVE-2025-54735 Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This issue affects CubeWP: from n/a… Mitigation only Fix from $1,9502025-08-20 CRITICAL 9.9 CVE-2025-54049 Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom … Mitigation only Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2025-53580 Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.… Mitigation only Fix from $2,3002025-08-20 CRITICAL 9.8 CVE-2025-49422 Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.This issue affects Support Tic… Mitigation only Fix from $2,3002025-08-20 HIGH 8.8 CVE-2025-48164 Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash suredash allows Privilege Escalation.This issue affects SureDash: from n/a … Mitigation only Fix from $1,9502025-08-20 HIGH 8.8 CVE-2025-48165 Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue affects DELUCKS SEO: from n/a … Mitigation only Fix from $1,9502025-08-20 HIGH 8.8 CVE-2025-48142 Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify bookify allows Privilege Escalation.This issue affects Bookify: from n/a through <… Mitigation only Fix from $1,9502025-08-20 MEDIUM 6.3 CVE-2025-9151 A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the function updateJsonValueByName of … No fix yet Fix from $1,6002025-08-19 MEDIUM 6.1 CVE-2025-5417 An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cl… Mitigation only Fix from $1,6002025-08-19 MEDIUM 6.5 CVE-2017-20199 A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an unknown functionality of the co… Buttercup 1.0.1+ Fix from $1,6002025-08-16