Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Orion Ops HIGH 8.8
CVE-2025-13808

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of …

Fix: after 2025-08-01
Fix from $1,950 2025-12-01
Nutzboot CRITICAL 9.8
CVE-2025-13806

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzbo…

Fix: after 2.6.0
Fix from $2,300 2025-12-01
Oneuptime HIGH 8.1
CVE-2025-65966

OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a dir…

No fix yet
Fix from $1,950 2025-11-26
Unclassified MEDIUM 5.4
CVE-2025-65963

Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow n…

Patch available
Fix from $1,600 2025-11-26
Project Contract Management CRITICAL 9.8
CVE-2025-64063

Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can e…

Mitigation only
Fix from $2,300 2025-11-25
Project Contract Management HIGH 8.8
CVE-2025-64065

The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or us…

Mitigation only
Fix from $1,950 2025-11-25
Project Contract Management HIGH 8.8
CVE-2025-64062

The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the aut…

Mitigation only
Fix from $1,950 2025-11-25
Blog Site HIGH 8.8
CVE-2025-13576

A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulat…

Mitigation only
Fix from $1,950 2025-11-24
Langfuse MEDIUM 6.5
CVE-2025-65107

Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in…

Fix: 2.95.12 / 3.131.0+
Fix from $1,600 2025-11-21
Helm Charts HIGH 8.8
CVE-2025-64751

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1…

Fix: 0.2.49 / 1.11.1+
Fix from $1,950 2025-11-21
Dynamics Omnichannel Sdk Storage Containers CRITICAL 9.8
CVE-2025-64655

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2025-11-20
Wbce Cms HIGH 8.8
CVE-2025-65094

WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrator…

Fix: 1.6.4+
Fix from $1,950 2025-11-19
Rallly HIGH 8.1
CVE-2025-65033

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any a…

Fix: 4.5.4+
Fix from $1,950 2025-11-19
Rallly MEDIUM 6.5
CVE-2025-65028

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a…

Fix: 4.5.4+
Fix from $1,600 2025-11-19
Rallly HIGH 8.1
CVE-2025-65029

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a…

Fix: 4.5.4+
Fix from $1,950 2025-11-19
Rallly HIGH 7.1
CVE-2025-65030

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment deletion API allows any auth…

Fix: 4.5.4+
Fix from $1,950 2025-11-19
Rallly MEDIUM 6.5
CVE-2025-65031

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in the comment creation endpoint a…

Fix: 4.5.4+
Fix from $1,600 2025-11-19
Rallly MEDIUM 6.5
CVE-2025-65020

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability in the p…

Fix: 4.5.4+
Fix from $1,600 2025-11-19
Rallly CRITICAL 9.1
CVE-2025-65021

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists i…

Fix: 4.5.4+
Fix from $2,300 2025-11-19
Wolf1ms Firmware CRITICAL 9.8
CVE-2025-63218

The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authenticat…

Fix: after 1.0.3
Fix from $2,300 2025-11-19
Unclassified MEDIUM 5.3
CVE-2025-12814

The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect capability check on the sites…

Mitigation only
Fix from $1,600 2025-11-19
Unclassified MEDIUM 5.3
CVE-2025-12777

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to…

Mitigation only
Fix from $1,600 2025-11-19
Mall MEDIUM 5.3
CVE-2025-13117

A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder …

Fix: after 1.0.3
Fix from $1,600 2025-11-13
Mall Swarm MEDIUM 5.3
CVE-2025-13114

A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /cart/update/attr. Such manipul…

Fix: after 1.0.3
Fix from $1,600 2025-11-13
Mall MEDIUM 5.3
CVE-2025-13115

A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the…

Fix: after 1.0.3
Fix from $1,600 2025-11-13
Mall MEDIUM 5.3
CVE-2025-13116

A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserO…

Fix: after 1.0.3
Fix from $1,600 2025-11-13
Filebrowser HIGH 8.8
CVE-2025-64523

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Ve…

Fix: 2.45.1+
Fix from $1,950 2025-11-12
Unclassified HIGH 8.1
CVE-2025-11521

The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of rem…

Mitigation only
Fix from $1,950 2025-11-11
Chrome MEDIUM 5.4
CVE-2025-12435

Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HT…

Fix: 142.0.7444.59+
Fix from $1,600 2025-11-10
Pig CRITICAL 9.6
CVE-2025-63691

In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/…

Fix: after 3.8.2
Fix from $2,300 2025-11-07