Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Chamilo Lms MEDIUM 5.4
CVE-2026-1106

A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Control…

Fix: 2.0.0+
Fix from $1,600 2026-01-18
Power Apps HIGH 8.0
CVE-2026-20960

Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

Fix: 3.25121+
Fix from $1,950 2026-01-16
Librechat CRITICAL 9.9
CVE-2026-22252

LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without valida…

Patch available
Fix from $2,300 2026-01-12
Rustfs HIGH 8.8
CVE-2026-22042

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `E…

No fix yet
Fix from $1,950 2026-01-08
Unclassified MEDIUM 5.1
CVE-2025-67603

A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This issue affects Foomuuri: from ? …

Mitigation only
Fix from $1,600 2026-01-08
Opencti CRITICAL 9.1
CVE-2025-61781

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "Wo…

Fix: 6.8.1+
Fix from $2,300 2026-01-05
Warehouse HIGH 8.8
CVE-2026-0574

A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file…

Fix: after 2025-10-06
Fix from $1,950 2026-01-04
Jeecg Boot HIGH 7.5
CVE-2025-15126

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position…

Fix: after 3.9.0
Fix from $1,950 2025-12-28
Youlai Mall HIGH 8.1
CVE-2025-15085

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/…

Mitigation only
Fix from $1,950 2025-12-25
Fastapi Users HIGH 8.8
CVE-2025-68481

FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login…

Fix: 15.0.2+
Fix from $1,950 2025-12-19
Unclassified MEDIUM 6.3
CVE-2025-14546

Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth sta…

Patch available
Fix from $1,600 2025-12-19
Partner Center CRITICAL 9.8
CVE-2025-65041

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-12-18
Advanced Voting Management System MEDIUM 6.3
CVE-2025-14889

A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admi…

No fix yet
Fix from $1,600 2025-12-18
Filemaker Server MEDIUM 5.4
CVE-2025-46296

An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative …

Fix: 22.0.4+
Fix from $1,600 2025-12-16
Pimp My Log CRITICAL 9.8
CVE-2023-53895

PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization throug…

Mitigation only
Fix from $2,300 2025-12-16
Wekan MEDIUM 6.5
CVE-2025-65782

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling …

Fix: after 8.15
Fix from $1,600 2025-12-15
macOS MEDIUM 5.5
CVE-2025-46289

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app m…

Fix: 14.8.3 / 15.7.3+
Fix from $1,600 2025-12-12
Sinec Security Monitor MEDIUM 6.7
CVE-2025-40830

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization c…

Fix: 4.10.0+
Fix from $1,600 2025-12-09
Online Student Clearance System HIGH 7.5
CVE-2025-14206

A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/…

No fix yet
Fix from $1,950 2025-12-08
Unclassified MEDIUM 5.3
CVE-2025-12720

The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the ha…

Mitigation only
Fix from $1,600 2025-12-06
Unclassified MEDIUM 5.4
CVE-2025-12505

The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This is due to the plugin not prop…

Mitigation only
Fix from $1,600 2025-12-06
Unclassified MEDIUM 6.3
CVE-2025-14089

A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the file /api/admin/update_account/ …

Mitigation only
Fix from $1,600 2025-12-05
Unclassified MEDIUM 6.3
CVE-2025-14088

A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of the file /je/load. This mani…

No fix yet
Fix from $1,600 2025-12-05
Mall Swarm HIGH 8.1
CVE-2025-14016

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/dele…

Fix: after 1.0.3
Fix from $1,950 2025-12-04
Terminalfour CRITICAL 9.8
CVE-2025-58386

In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks.…

Fix: 8.4.1.2+
Fix from $2,300 2025-12-02
Grav CRITICAL 9.6
CVE-2025-66301

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /…

Fix: 1.8.0+
Fix from $2,300 2025-12-01
Orion Ops HIGH 8.8
CVE-2025-13808

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of …

Fix: after 2025-08-01
Fix from $1,950 2025-12-01
Nutzboot CRITICAL 9.8
CVE-2025-13806

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzbo…

Fix: after 2.6.0
Fix from $2,300 2025-12-01
Oneuptime HIGH 8.1
CVE-2025-65966

OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a dir…

No fix yet
Fix from $1,950 2025-11-26
Unclassified MEDIUM 5.4
CVE-2025-65963

Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow n…

Patch available
Fix from $1,600 2025-11-26