Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Identity Services Engine HIGH 7.2
CVE-2025-20125EPSS 17%

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information…

Fix: 3.1+
Fix from $1,950 2025-02-05
Unclassified MEDIUM 6.5
CVE-2025-24376

kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy an…

Patch available
Fix from $1,600 2025-01-30
Single User Chat HIGH 8.1
CVE-2024-13646

The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient…

Fix: after 0.5
Fix from $1,950 2025-01-30
Woocommerce Wishlist HIGH 7.5
CVE-2024-13694

The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direc…

Fix: 1.8.8+
Fix from $1,950 2025-01-30
School Management Software HIGH 8.1
CVE-2025-0849

A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-…

No fix yet
Fix from $1,950 2025-01-30
Unclassified MEDIUM 5.6
CVE-2025-0580

A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of …

Mitigation only
Fix from $1,600 2025-01-20
Unclassified HIGH 8.7
CVE-2024-55954

OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Adm…

Mitigation only
Fix from $1,950 2025-01-16
Native Php Cms HIGH 7.5
CVE-2025-0484

A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown processing of the file /fladmin…

No fix yet
Fix from $1,950 2025-01-15
Gradio HIGH 7.5
CVE-2025-23042

Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Py…

Fix: 5.6.0+
Fix from $1,950 2025-01-14
Sharepoint Server HIGH 7.2
CVE-2025-21348

Microsoft SharePoint Server Remote Code Execution Vulnerability

Fix: 16.0.17928.20356+
Fix from $1,950 2025-01-14
Windows 10 21h2 HIGH 7.8
CVE-2025-21275

Windows App Package Installer Elevation of Privilege Vulnerability

Fix: 10.0.19044.5371 / 10.0.19045.5371+
Fix from $1,950 2025-01-14
Helm Charts CRITICAL 9.8
CVE-2024-56323

OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) a…

Fix: 0.2.19 / 1.8.3+
Fix from $2,300 2025-01-13
Open Social CRITICAL 9.1
CVE-2024-13241

Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.…

Fix: 12.0.5+
Fix from $2,300 2025-01-09
Tgstation Server HIGH 8.8
CVE-2025-21611

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd i…

Fix: 6.12.3+
Fix from $1,950 2025-01-06
Gocd HIGH 8.8
CVE-2024-56320

GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of acce…

Fix: 24.5.0+
Fix from $1,950 2025-01-03
Yunfan Learning Examination System MEDIUM 5.3
CVE-2024-13109

A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue a…

No fix yet
Fix from $1,600 2025-01-02
Unclassified HIGH 8.7
CVE-2024-56802

Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can gues…

Patch available
Fix from $1,950 2024-12-31
Mate 20 Firmware MEDIUM 6.8
CVE-2020-9081

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to expl…

Fix: 10.1.0.88 / 10.1.0.160+
Fix from $1,600 2024-12-27
Traffic Control HIGH 8.8
CVE-2024-45387EPSS 42%

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", …

Fix: 8.0.2+
Fix from $1,950 2024-12-23
Foxcms MEDIUM 5.3
CVE-2024-12901

A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api…

Fix: after 1.2
Fix from $1,600 2024-12-23
Vaultwarden HIGH 7.5
CVE-2024-56335

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable…

Fix: 1.32.7+
Fix from $1,950 2024-12-20
Unclassified HIGH 7.3
CVE-2024-12782

A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. Thi…

Mitigation only
Fix from $1,950 2024-12-19
Download Manager MEDIUM 5.3
CVE-2024-11768

The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on…

Fix: 3.3.04+
Fix from $1,600 2024-12-19
Next.js HIGH 7.5
CVE-2024-51479

Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in m…

Fix: 14.2.15+
Fix from $1,950 2024-12-17
Ujcms MEDIUM 5.9
CVE-2024-12483

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the comp…

Fix: 9.6.3+
Fix from $1,600 2024-12-12
Experience Manager MEDIUM 6.5
CVE-2024-43729

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature …

Fix: 6.5.22.0 / 2024.11.0+
Fix from $1,600 2024-12-10
Jeewms MEDIUM 5.3
CVE-2024-12347

A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown pr…

Mitigation only
Fix from $1,600 2024-12-09
Best House Rental Management System MEDIUM 6.5
CVE-2024-11860

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects an unknown part of the …

No fix yet
Fix from $1,600 2024-11-27
Zabbix HIGH 8.8
CVE-2024-36467

An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is en…

Fix: 5.0.43 / 6.0.33+
Fix from $1,950 2024-11-27
Unclassified HIGH 7.4
CVE-2024-8676

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it d…

Mitigation only
Fix from $1,950 2024-11-26