Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
I Educar HIGH 8.8
CVE-2025-9687

A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoA…

Fix: after 2.10
Fix from $1,950 2025-08-30
I Educar HIGH 8.8
CVE-2025-9609

A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulati…

Fix: after 2.10
Fix from $1,950 2025-08-29
Rockoa MEDIUM 6.5
CVE-2025-9602

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation result…

Fix: after 2.6.9
Fix from $1,600 2025-08-29
Pc Manager CRITICAL 9.8
CVE-2025-53795

Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-08-21
Unclassified MEDIUM 6.3
CVE-2025-9151

A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the function updateJsonValueByName of …

No fix yet
Fix from $1,600 2025-08-19
Unclassified CRITICAL 9.8
CVE-2025-7778

The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within…

Mitigation only
Fix from $2,300 2025-08-15
Superset MEDIUM 6.5
CVE-2025-55675

Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated use…

Fix: 5.0.0+
Fix from $1,600 2025-08-14
Jsherp MEDIUM 5.4
CVE-2025-8840

A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoi…

No fix yet
Fix from $1,600 2025-08-11
Jsherp HIGH 8.8
CVE-2025-8839

A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endp…

No fix yet
Fix from $1,950 2025-08-11
Litmus HIGH 7.8
CVE-2025-8794

A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown funct…

Fix: after 3.19.0
Fix from $1,950 2025-08-10
Litmus MEDIUM 6.3
CVE-2025-8791

A vulnerability was found in LitmusChaos Litmus up to 3.19.0. It has been rated as critical. This issue affects some unknown processing of the file /…

Fix: after 3.19.0
Fix from $1,600 2025-08-10
Tduck Platform HIGH 8.8
CVE-2025-8756

A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preH…

Fix: after 5.1
Fix from $1,950 2025-08-09
Mall MEDIUM 5.3
CVE-2025-8755

A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberC…

Fix: after 1.0.3
Fix from $1,600 2025-08-09
Azure Portal CRITICAL 9.1
CVE-2025-53792

Azure Portal Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-08-07
Pybbs MEDIUM 5.3
CVE-2025-8547

A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email …

Fix: after 6.0.0
Fix from $1,600 2025-08-05
Librechat HIGH 7.5
CVE-2025-54868

LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chat…

Fix: 0.7.8+
Fix from $1,950 2025-08-05
Cursor CRITICAL 9.8
CVE-2025-54130

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If…

Fix: 1.3.9+
Fix from $2,300 2025-08-05
Gitproxy MEDIUM 6.5
CVE-2025-54585

GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can exploit the way GitP…

Fix: 1.19.2+
Fix from $1,600 2025-07-30
Autogpt Platform HIGH 7.7
CVE-2025-53944

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external A…

Patch available
Fix from $1,950 2025-07-30
Vaelsys CRITICAL 9.8
CVE-2025-8261

A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the componen…

Mitigation only
Fix from $2,300 2025-07-28
Haxcms Nodejs HIGH 8.3
CVE-2025-54378

HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 …

Fix: 11.0.9 / 11.0.14+
Fix from $1,950 2025-07-26
Jsherp HIGH 8.1
CVE-2025-7947

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component …

Fix: after 3.5
Fix from $1,950 2025-07-22
Azure Machine Learning HIGH 8.8
CVE-2025-49746

Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-07-18
Opencti MEDIUM 5.4
CVE-2025-46732

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnerability in…

Fix: 6.6.6+
Fix from $1,600 2025-07-18
Weblogic Server MEDIUM 6.1
CVE-2025-50073

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are…

Patch available
Fix from $1,600 2025-07-15
Unclassified HIGH 8.7
CVE-2024-26291

An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path …

Mitigation only
Fix from $1,950 2025-07-14
Unclassified MEDIUM 5.4
CVE-2025-53709

Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The service only installed on a s…

Mitigation only
Fix from $1,600 2025-07-10
Juju HIGH 8.8
CVE-2025-0928

In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the c…

Fix: 2.9.52 / 3.6.8+
Fix from $1,950 2025-07-08
Juju MEDIUM 6.5
CVE-2025-53512

The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contai…

Fix: 2.9.52 / 3.6.8+
Fix from $1,600 2025-07-08
Sharepoint Server HIGH 8.8
CVE-2025-49701

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.18526.20424+
Fix from $1,950 2025-07-08