Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Jeecg Boot MEDIUM 6.5
CVE-2025-10978

A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /sys/user/exportXls of the comp…

Fix: after 3.8.2
Fix from $1,600 2025-09-25
Jeecg Boot MEDIUM 6.5
CVE-2025-10979

A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulati…

Fix: after 3.8.2
Fix from $1,600 2025-09-25
Jeecg Boot MEDIUM 5.3
CVE-2025-10977

A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteBatch. The manipulation of the…

Fix: after 3.8.2
Fix from $1,600 2025-09-25
Jeecg Boot MEDIUM 5.3
CVE-2025-10976

A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/getDepartUserList. Executing man…

Fix: after 3.8.2
Fix from $1,600 2025-09-25
Unclassified MEDIUM 5.3
CVE-2025-10947

A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of the file /api/areacliente/pe…

Mitigation only
Fix from $1,600 2025-09-25
Langfuse HIGH 7.6
CVE-2025-59305

Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control…

Fix: 3.109.0+
Fix from $1,950 2025-09-24
Ip 4c Firmware MEDIUM 6.8
CVE-2025-57438

The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only afte…

No fix yet
Fix from $1,600 2025-09-22
Qloapps MEDIUM 5.3
CVE-2025-10759

A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula…

Fix: after 1.7.0
Fix from $1,600 2025-09-21
Unclassified MEDIUM 6.4
CVE-2025-8532

Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workfl…

Mitigation only
Fix from $1,600 2025-09-19
Jeecg Boot HIGH 8.8
CVE-2025-10707

A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing m…

Fix: after 3.8.2
Fix from $1,950 2025-09-19
Unclassified MEDIUM 6.5
CVE-2025-8057

Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Improper Authorization vulnerabili…

Mitigation only
Fix from $1,600 2025-09-16
Unclassified HIGH 7.5
CVE-2025-41249

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized sup…

Mitigation only
Fix from $1,950 2025-09-16
macOS MEDIUM 5.5
CVE-2025-43231

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8. An app may be able to access user-sensitive data.

Fix: 14.8+
Fix from $1,600 2025-09-15
Ipados CRITICAL 9.8
CVE-2025-31255

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14…

Fix: 14.8 / 15.7+
Fix from $2,300 2025-09-15
Crmeb HIGH 8.8
CVE-2025-10390

A weakness has been identified in CRMEB up to 5.6.1. The affected element is the function editAddress of the file app/services/user/UserAddressServic…

Fix: after 5.6.1
Fix from $1,950 2025-09-14
Crmeb HIGH 8.8
CVE-2025-10389

A security flaw has been discovered in CRMEB up to 5.6.1. Impacted is the function Save of the file app/services/system/admin/SystemAdminServices.php…

Fix: after 5.6.1
Fix from $1,950 2025-09-14
Ruoyi MEDIUM 5.4
CVE-2025-10384

A flaw has been found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the file /system/role/authUse…

Fix: after 4.8.1
Fix from $1,600 2025-09-13
Unclassified HIGH 7.3
CVE-2025-10374

A security flaw has been discovered in Shenzhen Sixun Business Management System 7/11. This affects an unknown part of the file /Adm/OperatorStop. Pe…

No fix yet
Fix from $1,950 2025-09-13
Jeecg Boot MEDIUM 6.5
CVE-2025-10319

A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog …

Fix: after 3.8.2
Fix from $1,600 2025-09-12
Jeecg Boot HIGH 8.8
CVE-2025-10318

A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSo…

Fix: after 3.8.2
Fix from $1,950 2025-09-12
Litemall HIGH 8.8
CVE-2025-10291

A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. …

Fix: after 1.8.0
Fix from $1,950 2025-09-12
Ruoyi Vue Pro HIGH 8.8
CVE-2025-10278

A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of …

Fix: after 2025.09
Fix from $1,950 2025-09-12
Ruoyi Vue Pro HIGH 8.8
CVE-2025-10276

A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/t…

Fix: after 2025.09
Fix from $1,950 2025-09-12
Yudao Cloud HIGH 8.8
CVE-2025-10277

A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file /crm/receivable/submit. The …

Fix: after 2025.09
Fix from $1,950 2025-09-12
Yudao Cloud HIGH 8.8
CVE-2025-10275

A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Executing manipu…

Fix: after 2025.09
Fix from $1,950 2025-09-12
Unclassified MEDIUM 5.4
CVE-2025-10209

A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Ha…

Mitigation only
Fix from $1,600 2025-09-10
Platform MEDIUM 6.3
CVE-2025-10086

A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the c…

No fix yet
Fix from $1,600 2025-09-08
Android HIGH 7.8
CVE-2025-26430

In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to loca…

Patch available
Fix from $1,950 2025-09-04
Unclassified MEDIUM 5.4
CVE-2025-9937

A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulat…

Mitigation only
Fix from $1,600 2025-09-04
I Educar HIGH 8.8
CVE-2025-9760

A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Mat…

Fix: after 2.10.0
Fix from $1,950 2025-09-01