Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Unclassified MEDIUM 5.3
CVE-2025-53532

giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauthorized user to create discuss…

Patch available
Fix from $1,600 2025-07-07
MongoDB MEDIUM 6.5
CVE-2025-6713

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of th…

Fix: 6.0.22 / 7.0.19+
Fix from $1,600 2025-07-07
Graylog HIGH 8.8
CVE-2025-53106

Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain …

Fix: 6.2.4+
Fix from $1,950 2025-07-02
Cms HIGH 8.8
CVE-2025-6736

A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-…

No fix yet
Fix from $1,950 2025-06-27
Cms HIGH 8.8
CVE-2025-6735

A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the comp…

No fix yet
Fix from $1,950 2025-06-27
Litemall MEDIUM 5.3
CVE-2025-6702

A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment…

No fix yet
Fix from $1,600 2025-06-26
Identity Services Engine MEDIUM 6.4
CVE-2025-20264

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass…

Mitigation only
Fix from $1,600 2025-06-25
Firefox MEDIUM 6.5
CVE-2025-6431

When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have b…

Fix: 140.0+
Fix from $1,600 2025-06-24
Real Estate Management System HIGH 8.1
CVE-2025-6329

A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown process…

No fix yet
Fix from $1,950 2025-06-20
Unclassified MEDIUM 5.3
CVE-2025-6099

A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared as critical. This vulnerabili…

Mitigation only
Fix from $1,600 2025-06-16
Unclassified HIGH 8.1
CVE-2025-22239

Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the …

Mitigation only
Fix from $1,950 2025-06-13
Experience Manager HIGH 8.7
CVE-2025-46840

Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalatio…

Fix: 6.5.23.0 / 2025.5.0+
Fix from $1,950 2025-06-10
Kibana HIGH 8.8
CVE-2024-43706

Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

Fix: after 8.12.0
Fix from $1,950 2025-06-10
Commerce HIGH 8.2
CVE-2025-43585

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that cou…

Mitigation only
Fix from $1,950 2025-06-10
Unclassified HIGH 7.3
CVE-2025-5522

A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affe…

Mitigation only
Fix from $1,950 2025-06-03
Shiyi Blog HIGH 7.5
CVE-2025-5511

A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of…

Fix: after 1.2.1
Fix from $1,950 2025-06-03
Unclassified MEDIUM 5.0
CVE-2025-3454

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. …

Mitigation only
Fix from $1,600 2025-06-02
Unclassified CRITICAL 9.8
CVE-2025-4631

The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versio…

Mitigation only
Fix from $2,300 2025-05-31
Unclassified HIGH 8.8
CVE-2025-4672

The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback…

Mitigation only
Fix from $1,950 2025-05-31
Unclassified HIGH 8.8
CVE-2025-4103

The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_ajax_wpgm_start_geojson_import(…

Mitigation only
Fix from $1,950 2025-05-31
Vacation Rental Management Platform HIGH 7.5
CVE-2025-5182

A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability a…

Fix: 1.0.2+
Fix from $1,950 2025-05-26
Pypickle MEDIUM 5.5
CVE-2025-5175

A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the function Save of the file pypickle/p…

Fix: 2.0.0+
Fix from $1,600 2025-05-26
Helm Charts HIGH 8.8
CVE-2025-48371

OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.…

Fix: 0.2.32 / 1.8.13+
Fix from $1,950 2025-05-22
Xwiki HIGH 8.8
CVE-2025-48063

XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part of the s…

Fix: 16.10.4+
Fix from $1,950 2025-05-21
Unclassified HIGH 8.8
CVE-2025-4473

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in…

Mitigation only
Fix from $1,950 2025-05-13
Unclassified HIGH 8.8
CVE-2025-4474

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_fun…

Mitigation only
Fix from $1,950 2025-05-13
macOS HIGH 7.1
CVE-2025-31249

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data.

Fix: 15.5+
Fix from $1,950 2025-05-12
Azure Automation HIGH 8.8
CVE-2025-29827

Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-05-08
Unclassified CRITICAL 9.8
CVE-2025-4104

The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form…

Mitigation only
Fix from $2,300 2025-05-07
Unclassified HIGH 8.2
CVE-2025-3921

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mitigation only
Fix from $1,950 2025-05-07