Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Idonate HIGH 8.8
CVE-2025-4519

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capabil…

Fix: 2.1.10+
Fix from $1,950 2025-11-07
Voluntary Like System MEDIUM 6.5
CVE-2025-60784

A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.php Pay m…

No fix yet
Fix from $1,600 2025-11-05
Unclassified MEDIUM 5.3
CVE-2025-11174

The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to th…

Mitigation only
Fix from $1,600 2025-11-01
Pharmacare HIGH 8.8
CVE-2025-12288

A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the comp…

Fix: after 9.4
Fix from $1,950 2025-10-27
Client Details System HIGH 8.1
CVE-2025-12283

A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown function. The manipulation results…

No fix yet
Fix from $1,950 2025-10-27
Unclassified MEDIUM 5.4
CVE-2025-6639

The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to…

Mitigation only
Fix from $1,600 2025-10-25
Unclassified MEDIUM 6.5
CVE-2025-11879

The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_option_rest' funct…

Mitigation only
Fix from $1,600 2025-10-25
Hono HIGH 8.1
CVE-2025-62610

Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middle…

Fix: 4.10.2+
Fix from $1,950 2025-10-22
Jira Align MEDIUM 5.4
CVE-2025-22169

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive in…

Fix: 11.16.1+
Fix from $1,600 2025-10-22
Jira Align MEDIUM 5.4
CVE-2025-22175

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive in…

Fix: 11.16.1+
Fix from $1,600 2025-10-22
Jd Edwards Enterpriseone Tools MEDIUM 6.1
CVE-2025-53056

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Object and Environment Tech). Supported versions that a…

Fix: after 9.2.9.4
Fix from $1,600 2025-10-21
Unclassified MEDIUM 5.3
CVE-2025-11256

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions …

Mitigation only
Fix from $1,600 2025-10-18
Unclassified CRITICAL 9.3
CVE-2025-61928EPSS 18%

Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modif…

Patch available
Fix from $2,300 2025-10-09
Azure Cache For Redis HIGH 8.7
CVE-2025-59271

Redis Enterprise Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2025-10-09
Unclassified HIGH 7.2
CVE-2025-61524

An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, a…

Patch available
Fix from $1,950 2025-10-08
Unclassified CRITICAL 9.2
CVE-2025-49594

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW…

Patch available
Fix from $2,300 2025-10-06
Unclassified MEDIUM 5.4
CVE-2025-11272

A vulnerability has been found in SeriaWei ZKEACMS up to 4.3. This affects the function Delete of the file src/ZKEACMS.Redirection/Controllers/UrlRed…

Mitigation only
Fix from $1,600 2025-10-04
Givewp MEDIUM 6.5
CVE-2025-11227

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including…

Fix: 4.10.1+
Fix from $1,600 2025-10-04
Unclassified MEDIUM 6.5
CVE-2025-59686

Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id.

Mitigation only
Fix from $1,600 2025-10-01
I Educar HIGH 8.8
CVE-2025-11050

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lea…

Fix: after 2.10.0
Fix from $1,950 2025-09-27
I Educar HIGH 8.8
CVE-2025-11049

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /unificacao-aluno. P…

Fix: after 2.10.0
Fix from $1,950 2025-09-27
I Educar HIGH 8.8
CVE-2025-11048

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file …

Fix: after 2.10.0
Fix from $1,950 2025-09-26
I Educar HIGH 8.8
CVE-2025-11047

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of…

Fix: after 2.10.0
Fix from $1,950 2025-09-26
Unclassified HIGH 7.3
CVE-2025-11030

A vulnerability was detected in Tutorials-Website Employee Management System up to 611887d8f8375271ce8abc704507d46340837a60. Impacted is an unknown f…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified MEDIUM 5.3
CVE-2025-10992

A vulnerability was determined in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. Affected is an unknown function of the file /user…

Mitigation only
Fix from $1,600 2025-09-26
Ruoyi Vue Pro HIGH 8.8
CVE-2025-10988

A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Such manipulat…

Fix: after 2025.09
Fix from $1,950 2025-09-26
Ruoyi HIGH 8.8
CVE-2025-10989

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/sel…

Fix: after 4.8.1
Fix from $1,950 2025-09-26
Jeecg Boot MEDIUM 6.5
CVE-2025-10981

A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Performing manipulation re…

Fix: after 3.8.2
Fix from $1,600 2025-09-26
Yudao Cloud HIGH 8.8
CVE-2025-10987

A vulnerability was determined in YunaiV yudao-cloud up to 2025.09. Affected by this issue is some unknown functionality of the file /crm/contact/tra…

Fix: after 2025.09
Fix from $1,950 2025-09-26
Jeecg Boot MEDIUM 6.5
CVE-2025-10980

A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manip…

Fix: after 3.8.2
Fix from $1,600 2025-09-26