Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Java Virtual Machine MEDIUM 5.9
CVE-2025-61881

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Di…

Fix: after 23.9
Fix from $1,600 2025-10-21
Peoplesoft Enterprise Fin It Asset Management MEDIUM 6.5
CVE-2025-61758

Vulnerability in the PeopleSoft Enterprise FIN IT Asset Management product of Oracle PeopleSoft (component: IT Asset Management). The supported ver…

Mitigation only
Fix from $1,600 2025-10-21
Vm Virtualbox HIGH 7.5
CVE-2025-61760

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7…

Mitigation only
Fix from $1,950 2025-10-21
Peoplesoft Enterprise Fin Maintenance Management MEDIUM 5.4
CVE-2025-61761

Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supporte…

Mitigation only
Fix from $1,600 2025-10-21
Peoplesoft Enterprise Fin Payables MEDIUM 6.3
CVE-2025-61762

Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Payables). The supported version that is affected …

Mitigation only
Fix from $1,600 2025-10-21
Essbase HIGH 8.1
CVE-2025-61763

Vulnerability in Oracle Essbase (component: Essbase Web Platform). The supported version that is affected is 21.7.3.0.0. Easily exploitable vulnera…

Mitigation only
Fix from $1,950 2025-10-21
Peoplesoft Enterprise Peopletools MEDIUM 5.5
CVE-2025-53061

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are af…

Fix: after 8.62
Fix from $1,600 2025-10-21
Graalvm MEDIUM 5.9
CVE-2025-53057

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp…

Mitigation only
Fix from $1,600 2025-10-21
Applications Manager MEDIUM 6.1
CVE-2025-53058

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Application Logging Interfaces). Supported versions …

Fix: after 12.2.14
Fix from $1,600 2025-10-21
Jd Edwards Enterpriseone Tools MEDIUM 6.1
CVE-2025-53060

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …

Fix: after 9.2.9.4
Fix from $1,600 2025-10-21
Workflow MEDIUM 6.1
CVE-2025-53052

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affec…

Fix: after 12.2.14
Fix from $1,600 2025-10-21
Business Intelligence HIGH 8.4
CVE-2025-53049

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supporte…

Mitigation only
Fix from $1,950 2025-10-21
Istore MEDIUM 6.1
CVE-2025-53041

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.5-12…

Fix: after 12.2.14
Fix from $1,600 2025-10-21
Financial Services Revenue Management And Billing MEDIUM 6.5
CVE-2025-50075

Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Security …

Fix: after 7.2.0.0.0
Fix from $1,600 2025-10-21
Dir 820l Firmware HIGH 8.8
CVE-2025-52079

The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via …

No fix yet
Fix from $1,950 2025-10-21
Financial Services Analytical Applications Infrastructure MEDIUM 6.5
CVE-2025-53035

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P…

Mitigation only
Fix from $1,600 2025-10-21
Unclassified MEDIUM 6.5
CVE-2025-60427

LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can access analytics data via the…

Mitigation only
Fix from $1,600 2025-10-21
Filerise HIGH 8.1
CVE-2025-62509

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw…

Fix: 1.4.0+
Fix from $1,950 2025-10-20
Filerise HIGH 8.1
CVE-2025-62510

FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder…

Fix: 1.5.0+
Fix from $1,950 2025-10-20
Signinghub HIGH 7.1
CVE-2025-56219

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resourc…

Fix: after 8.6.8
Fix from $1,950 2025-10-20
Streamax Crocus HIGH 8.8
CVE-2025-11908

A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the fil…

No fix yet
Fix from $1,950 2025-10-17
Unclassified CRITICAL 9.1
CVE-2025-57567

A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default them…

Mitigation only
Fix from $2,300 2025-10-17
Teedy HIGH 8.1
CVE-2025-11853

A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Exe…

Fix: after 1.11
Fix from $1,950 2025-10-16
Strapi MEDIUM 6.5
CVE-2025-53092

Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default…

Fix: 5.20.0+
Fix from $1,600 2025-10-16
Webmin HIGH 7.1
CVE-2025-61541

Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is construc…

No fix yet
Fix from $1,950 2025-10-16
Unclassified HIGH 7.1
CVE-2025-61543

A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` direc…

Mitigation only
Fix from $1,950 2025-10-16
Api Control Plane MEDIUM 6.5
CVE-2025-9804

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin S…

Mitigation only
Fix from $1,600 2025-10-16
macOS MEDIUM 5.5
CVE-2025-43313

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app …

Fix: 13.7.7 / 14.7.7+
Fix from $1,600 2025-10-15
Azure Monitor Agent HIGH 7.8
CVE-2025-59494

Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

Fix: 1.38.1+
Fix from $1,950 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-59253

Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14