Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.9 CVE-2025-61881 Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Di… Java Virtual Machine after 23.9 Fix from $1,6002025-10-21 MEDIUM 6.5 CVE-2025-61758 Vulnerability in the PeopleSoft Enterprise FIN IT Asset Management product of Oracle PeopleSoft (component: IT Asset Management). The supported ver… Peoplesoft Enterprise Fin It Asset Management Mitigation only Fix from $1,6002025-10-21 HIGH 7.5 CVE-2025-61760 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7… Vm Virtualbox Mitigation only Fix from $1,9502025-10-21 MEDIUM 5.4 CVE-2025-61761 Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft (component: Work Order Management). The supporte… Peoplesoft Enterprise Fin Maintenance Management Mitigation only Fix from $1,6002025-10-21 MEDIUM 6.3 CVE-2025-61762 Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component: Payables). The supported version that is affected … Peoplesoft Enterprise Fin Payables Mitigation only Fix from $1,6002025-10-21 HIGH 8.1 CVE-2025-61763 Vulnerability in Oracle Essbase (component: Essbase Web Platform). The supported version that is affected is 21.7.3.0.0. Easily exploitable vulnera… Essbase Mitigation only Fix from $1,9502025-10-21 MEDIUM 5.5 CVE-2025-53061 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are af… Peoplesoft Enterprise Peopletools after 8.62 Fix from $1,6002025-10-21 MEDIUM 5.9 CVE-2025-53057 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp… Graalvm Mitigation only Fix from $1,6002025-10-21 MEDIUM 6.1 CVE-2025-53058 Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Application Logging Interfaces). Supported versions … Applications Manager after 12.2.14 Fix from $1,6002025-10-21 MEDIUM 6.1 CVE-2025-53060 Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected … Jd Edwards Enterpriseone Tools after 9.2.9.4 Fix from $1,6002025-10-21 MEDIUM 6.1 CVE-2025-53052 Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affec… Workflow after 12.2.14 Fix from $1,6002025-10-21 HIGH 8.4 CVE-2025-53049 Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supporte… Business Intelligence Mitigation only Fix from $1,9502025-10-21 MEDIUM 6.1 CVE-2025-53041 Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.5-12… Istore after 12.2.14 Fix from $1,6002025-10-21 MEDIUM 6.5 CVE-2025-50075 Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Security … Financial Services Revenue Management And Billing after 7.2.0.0.0 Fix from $1,6002025-10-21 HIGH 8.8 CVE-2025-52079 The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via … Dir 820l Firmware No fix yet Fix from $1,9502025-10-21 MEDIUM 6.5 CVE-2025-53035 Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: P… Financial Services Analytical Applications Infrastructure Mitigation only Fix from $1,6002025-10-21 MEDIUM 6.5 CVE-2025-60427 LibreTime 3.0.0-alpha.10 and possibly earlier is vulnerable to Broken Access Control, where a user with the DJ role can access analytics data via the… Mitigation only Fix from $1,6002025-10-21 HIGH 8.1 CVE-2025-62509 FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw… Filerise 1.4.0+ Fix from $1,9502025-10-20 HIGH 8.1 CVE-2025-62510 FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0, a regression allowed folder… Filerise 1.5.0+ Fix from $1,9502025-10-20 HIGH 7.1 CVE-2025-56219 Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resourc… Signinghub after 8.6.8 Fix from $1,9502025-10-20 HIGH 8.8 CVE-2025-11908 A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. The affected element is the function uploadFile of the fil… Streamax Crocus No fix yet Fix from $1,9502025-10-17 CRITICAL 9.1 CVE-2025-57567 A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default them… Mitigation only Fix from $2,3002025-10-17 HIGH 8.1 CVE-2025-11853 A vulnerability was determined in Sismics Teedy up to 1.11. This affects an unknown function of the file /api/file of the component API Endpoint. Exe… Teedy after 1.11 Fix from $1,9502025-10-16 MEDIUM 6.5 CVE-2025-53092 Strapi is an open source headless content management system. Strapi versions prior to 5.20.0 contain a CORS misconfiguration vulnerability in default… Strapi 5.20.0+ Fix from $1,6002025-10-16 HIGH 7.1 CVE-2025-61541 Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is construc… Webmin No fix yet Fix from $1,9502025-10-16 HIGH 7.1 CVE-2025-61543 A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` direc… Mitigation only Fix from $1,9502025-10-16 MEDIUM 6.5 CVE-2025-9804 An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin S… Api Control Plane Mitigation only Fix from $1,6002025-10-16 MEDIUM 5.5 CVE-2025-43313 A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app … macOS 13.7.7 / 14.7.7+ Fix from $1,6002025-10-15 HIGH 7.8 CVE-2025-59494 Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. Azure Monitor Agent 1.38.1+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-59253 Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14