Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.0 CVE-2025-52289 A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted reque… Magnusbilling Patch available Fix from $1,9502025-07-31 HIGH 7.8 CVE-2025-43256 This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to gai… macOS 14.7.7 / 15.6+ Fix from $1,9502025-07-30 HIGH 7.8 CVE-2025-43248 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able t… macOS 14.7.7 / 15.6+ Fix from $1,9502025-07-30 HIGH 7.8 CVE-2025-43249 A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be… macOS 13.7.7 / 14.7.7+ Fix from $1,9502025-07-30 CRITICAL 9.8 CVE-2025-43199 A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7… macOS 13.7.7 / 14.7.7+ Fix from $2,3002025-07-30 HIGH 7.8 CVE-2025-43188 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious app may be able to gain root p… macOS 15.6+ Fix from $1,9502025-07-30 HIGH 7.8 CVE-2025-31243 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7.… macOS 13.7.7 / 14.7.7+ Fix from $1,9502025-07-30 HIGH 7.8 CVE-2025-24119 This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An … macOS 13.7.7 / 14.7.7+ Fix from $1,9502025-07-30 HIGH 8.5 CVE-2024-13975 A local privilege escalation vulnerability exists in Commvault for Windows versions 11.20.0, 11.28.0, 11.32.0, 11.34.0, and 11.36.0. In affected conf… Mitigation only Fix from $1,9502025-07-25 MEDIUM 6.5 CVE-2024-48730 The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions on the authentication attemp… Mitigation only Fix from $1,6002025-07-25 HIGH 7.1 CVE-2024-48729 An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote authenticated attacker to esca… Mitigation only Fix from $1,9502025-07-25 HIGH 7.3 CVE-2025-22165 This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Ex… Sourcetree after 4.2.12 Fix from $1,9502025-07-24 MEDIUM 6.3 CVE-2025-8107 In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefu… Mitigation only Fix from $1,6002025-07-24 HIGH 7.4 CVE-2025-53942 authentik is an open-source Identity Provider that emphasizes flexibility and versatility, with support for a wide set of protocols. In versions 2025… Authentik 2025.4.4 / 2025.6.4+ Fix from $1,9502025-07-23 HIGH 8.5 CVE-2016-15045 A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepi… No fix yet Fix from $1,9502025-07-23 CRITICAL 9.3 CVE-2025-34143EPSS 31% An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal S… Mitigation only Fix from $2,3002025-07-22 HIGH 8.8 CVE-2025-46116 An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, … Ruckus Unleashed 10.5.1.0.279 / 200.15.6.212.14+ Fix from $1,9502025-07-21 HIGH 8.8 CVE-2015-10139 The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This make… Wordpress Learning Management System 1.8.9+ Fix from $1,9502025-07-19 MEDIUM 6.5 CVE-2025-7784 A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative use… Build Of Keycloak Mitigation only Fix from $1,6002025-07-18 MEDIUM 6.0 CVE-2025-53030 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas… Vm Virtualbox Mitigation only Fix from $1,6002025-07-15 HIGH 8.2 CVE-2025-53024 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas… Vm Virtualbox Mitigation only Fix from $1,9502025-07-15 MEDIUM 6.0 CVE-2025-53025 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas… Vm Virtualbox Mitigation only Fix from $1,6002025-07-15 MEDIUM 6.0 CVE-2025-53026 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas… Vm Virtualbox Mitigation only Fix from $1,6002025-07-15 HIGH 8.2 CVE-2025-53027 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.10. Eas… Vm Virtualbox Mitigation only Fix from $1,9502025-07-15 HIGH 7.7 CVE-2025-50069 Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 and 21.3-21.18. Easily exploi… Java Virtual Machine after 21.18 Fix from $1,9502025-07-15 MEDIUM 5.4 CVE-2025-50061 Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Su… Primavera P6 Enterprise Project Portfolio Management after 24.12.4 Fix from $1,6002025-07-15 HIGH 8.1 CVE-2025-50062 Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported vers… Peoplesoft Enterprise Hcm Global Payroll Core Patch available Fix from $1,9502025-07-15 CRITICAL 9.8 CVE-2025-7341 The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion… Download Contact Form 7 Widget For Elementor Page Builder \& Gutenberg Blocks 2.2.2+ Fix from $2,3002025-07-15 HIGH 7.2 CVE-2025-50124 A CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation when the server is accessed by a privileged … Mitigation only Fix from $1,9502025-07-11 MEDIUM 6.8 CVE-2025-5028 Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do… Mitigation only Fix from $1,6002025-07-11