Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Magnusbilling HIGH 8.0
CVE-2025-52289

A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted reque…

Patch available
Fix from $1,950 2025-07-31
macOS HIGH 7.8
CVE-2025-43256

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to gai…

Fix: 14.7.7 / 15.6+
Fix from $1,950 2025-07-30
macOS HIGH 7.8
CVE-2025-43248

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able t…

Fix: 14.7.7 / 15.6+
Fix from $1,950 2025-07-30
macOS HIGH 7.8
CVE-2025-43249

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be…

Fix: 13.7.7 / 14.7.7+
Fix from $1,950 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43199

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7…

Fix: 13.7.7 / 14.7.7+
Fix from $2,300 2025-07-30
macOS HIGH 7.8
CVE-2025-43188

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root p…

Fix: 15.6+
Fix from $1,950 2025-07-30
macOS HIGH 7.8
CVE-2025-31243

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.…

Fix: 13.7.7 / 14.7.7+
Fix from $1,950 2025-07-30
macOS HIGH 7.8
CVE-2025-24119

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An …

Fix: 13.7.7 / 14.7.7+
Fix from $1,950 2025-07-30
Unclassified HIGH 8.5
CVE-2024-13975

A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected conf…

Mitigation only
Fix from $1,950 2025-07-25
Unclassified MEDIUM 6.5
CVE-2024-48730

The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions on the authentication attemp…

Mitigation only
Fix from $1,600 2025-07-25
Unclassified HIGH 7.1
CVE-2024-48729

An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote authenticated attacker to esca…

Mitigation only
Fix from $1,950 2025-07-25
Sourcetree HIGH 7.3
CVE-2025-22165

This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Ex…

Fix: after 4.2.12
Fix from $1,950 2025-07-24
Unclassified MEDIUM 6.3
CVE-2025-8107

In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefu…

Mitigation only
Fix from $1,600 2025-07-24
Authentik HIGH 7.4
CVE-2025-53942

authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025…

Fix: 2025.4.4 / 2025.6.4+
Fix from $1,950 2025-07-23
Unclassified HIGH 8.5
CVE-2016-15045

A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepi…

No fix yet
Fix from $1,950 2025-07-23
Unclassified CRITICAL 9.3
CVE-2025-34143EPSS 31%

An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal S…

Mitigation only
Fix from $2,300 2025-07-22
Ruckus Unleashed HIGH 8.8
CVE-2025-46116

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, …

Fix: 10.5.1.0.279 / 200.15.6.212.14+
Fix from $1,950 2025-07-21
Wordpress Learning Management System HIGH 8.8
CVE-2015-10139

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This make…

Fix: 1.8.9+
Fix from $1,950 2025-07-19
Build Of Keycloak MEDIUM 6.5
CVE-2025-7784

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative use…

Mitigation only
Fix from $1,600 2025-07-18
Vm Virtualbox MEDIUM 6.0
CVE-2025-53030

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas…

Mitigation only
Fix from $1,600 2025-07-15
Vm Virtualbox HIGH 8.2
CVE-2025-53024

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas…

Mitigation only
Fix from $1,950 2025-07-15
Vm Virtualbox MEDIUM 6.0
CVE-2025-53025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas…

Mitigation only
Fix from $1,600 2025-07-15
Vm Virtualbox MEDIUM 6.0
CVE-2025-53026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas…

Mitigation only
Fix from $1,600 2025-07-15
Vm Virtualbox HIGH 8.2
CVE-2025-53027

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas…

Mitigation only
Fix from $1,950 2025-07-15
Java Virtual Machine HIGH 7.7
CVE-2025-50069

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. Easily exploi…

Fix: after 21.18
Fix from $1,950 2025-07-15
Primavera P6 Enterprise Project Portfolio Management MEDIUM 5.4
CVE-2025-50061

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Su…

Fix: after 24.12.4
Fix from $1,600 2025-07-15
Peoplesoft Enterprise Hcm Global Payroll Core HIGH 8.1
CVE-2025-50062

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported vers…

Patch available
Fix from $1,950 2025-07-15
Download Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks CRITICAL 9.8
CVE-2025-7341

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion…

Fix: 2.2.2+
Fix from $2,300 2025-07-15
Unclassified HIGH 7.2
CVE-2025-50124

A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged …

Mitigation only
Fix from $1,950 2025-07-11
Unclassified MEDIUM 6.8
CVE-2025-5028

Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do…

Mitigation only
Fix from $1,600 2025-07-11