Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Unclassified MEDIUM 5.3
CVE-2025-3924

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its publicly exposed reset-password end…

Mitigation only
Fix from $1,600 2025-05-07
Unclassified CRITICAL 9.8
CVE-2025-3918

The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in ve…

Mitigation only
Fix from $2,300 2025-05-03
Unclassified HIGH 7.3
CVE-2025-4210

A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers…

Patch available
Fix from $1,950 2025-05-02
Unclassified MEDIUM 5.4
CVE-2025-4136

A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the component Sale Endpoint. The…

Mitigation only
Fix from $1,600 2025-04-30
Azure Ai Bot Service CRITICAL 9.8
CVE-2025-30389

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-04-30
Azure Machine Learning HIGH 8.8
CVE-2025-30390

Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2025-04-30
Azure Ai Bot Service CRITICAL 9.8
CVE-2025-30392

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-04-30
Xwiki MEDIUM 5.3
CVE-2025-32972

XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc…

Fix: 15.10.12 / 16.4.3+
Fix from $1,600 2025-04-30
Novel Plus CRITICAL 9.1
CVE-2025-4016

A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the functio…

Fix: 5.1.1+
Fix from $2,300 2025-04-28
Novel Plus MEDIUM 6.5
CVE-2025-4017

A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This vulnerability affects…

Fix: after 5.1.1
Fix from $1,600 2025-04-28
Internet Doctor Workstation System MEDIUM 5.3
CVE-2025-3981

A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. T…

No fix yet
Fix from $1,600 2025-04-27
Internet Doctor Workstation System MEDIUM 5.3
CVE-2025-3980

A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability…

No fix yet
Fix from $1,600 2025-04-27
Paicoding MEDIUM 5.4
CVE-2025-3967

A vulnerability was found in itwanger paicoding 1.0.3. It has been classified as critical. This affects an unknown part of the file /article/api/post…

No fix yet
Fix from $1,600 2025-04-27
Ngeniusone HIGH 7.5
CVE-2025-32982

NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.

Fix: 6.4.0+
Fix from $1,950 2025-04-25
Xy 3820 Firmware CRITICAL 9.8
CVE-2025-29659

Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.

No fix yet
Fix from $2,300 2025-04-21
Studentmanager HIGH 8.8
CVE-2025-3587

A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /ge…

No fix yet
Fix from $1,950 2025-04-14
Db Hospital Drug MEDIUM 6.3
CVE-2025-3569

A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this issue is some unknown functiona…

No fix yet
Fix from $1,600 2025-04-14
Studentmanager MEDIUM 6.5
CVE-2025-3564

A vulnerability classified as problematic has been found in huanfenz/code-projects StudentManager up to 1.0. This affects an unknown part of the comp…

No fix yet
Fix from $1,600 2025-04-14
Employee Management System MEDIUM 6.5
CVE-2025-3536

A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown func…

No fix yet
Fix from $1,600 2025-04-13
Employee Management System MEDIUM 5.3
CVE-2025-3537

A vulnerability was found in Tutorials-Website Employee Management System 1.0. It has been classified as critical. This affects an unknown part of th…

No fix yet
Fix from $1,600 2025-04-13
Sharepoint Enterprise Server HIGH 8.8
CVE-2025-29794

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Fix: 16.0.18526.20172+
Fix from $1,950 2025-04-08
Graylog MEDIUM 5.3
CVE-2025-30373

Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and ha…

Fix: 6.1.9+
Fix from $1,600 2025-04-07
Ruoyi Ai CRITICAL 9.1
CVE-2025-3202

A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoy…

Fix: 2.0.1+
Fix from $2,300 2025-04-04
Ruoyi Ai CRITICAL 9.8
CVE-2025-3199

A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the fil…

Fix: 2.0.2+
Fix from $2,300 2025-04-04
Azure Playwright CRITICAL 9.8
CVE-2025-26683

Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2025-03-31
Unclassified HIGH 8.3
CVE-2025-3014

Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipu…

Mitigation only
Fix from $1,950 2025-03-31
Unclassified HIGH 8.3
CVE-2025-3013

Insecure Direct Object References (IDOR) in access control in Customer Portal before 2.1.4 on NightWolf Penetration Testing allows an attacker to acc…

Mitigation only
Fix from $1,950 2025-03-31
Remote Desktop Manager MEDIUM 6.8
CVE-2025-2600

Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PA…

Fix: 2024.3.31.0 / 2025.1.26.0+
Fix from $1,600 2025-03-26
Kyverno HIGH 8.0
CVE-2025-29778

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and I…

Fix: 1.13.6+
Fix from $1,950 2025-03-24
Jizhicms MEDIUM 5.3
CVE-2025-2639

A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/relea…

Fix: after 1.7
Fix from $1,600 2025-03-23