Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 5.3 CVE-2025-14348 The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to auth… Mitigation only Fix from $1,6002026-01-20 HIGH 8.8 CVE-2026-1193 A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View… Mineadmin No fix yet Fix from $1,9502026-01-19 HIGH 8.8 CVE-2026-1141 A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the… News Portal No fix yet Fix from $1,9502026-01-19 HIGH 8.1 CVE-2026-1112 A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/public… Publiccms after 5.202506.d Fix from $1,9502026-01-18 MEDIUM 5.4 CVE-2026-1106 A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Control… Chamilo Lms 2.0.0+ Fix from $1,6002026-01-18 HIGH 8.0 CVE-2026-20960 Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. Power Apps 3.25121+ Fix from $1,9502026-01-16 CRITICAL 9.9 CVE-2026-22252 LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without valida… Librechat Patch available Fix from $2,3002026-01-12 HIGH 8.8 CVE-2026-22042 RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `E… Rustfs No fix yet Fix from $1,9502026-01-08 MEDIUM 5.1 CVE-2025-67603 A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This issue affects Foomuuri: from ? … Mitigation only Fix from $1,6002026-01-08 CRITICAL 9.1 CVE-2025-61781 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.8.1, the GraphQL mutation "Wo… Opencti 6.8.1+ Fix from $2,3002026-01-05 HIGH 8.8 CVE-2026-0574 A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file… Warehouse after 2025-10-06 Fix from $1,9502026-01-04 HIGH 7.5 CVE-2025-15126 A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position… Jeecg Boot after 3.9.0 Fix from $1,9502025-12-28 HIGH 8.1 CVE-2025-15085 A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/… Youlai Mall Mitigation only Fix from $1,9502025-12-25 HIGH 8.8 CVE-2025-68481 FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login… Fastapi Users 15.0.2+ Fix from $1,9502025-12-19 MEDIUM 6.3 CVE-2025-14546 Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth sta… Patch available Fix from $1,6002025-12-19 CRITICAL 9.8 CVE-2025-65041 Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. Partner Center Mitigation only Fix from $2,3002025-12-18 MEDIUM 6.3 CVE-2025-14889 A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admi… Advanced Voting Management System No fix yet Fix from $1,6002025-12-18 MEDIUM 5.4 CVE-2025-46296 An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative … Filemaker Server 22.0.4+ Fix from $1,6002025-12-16 CRITICAL 9.8 CVE-2023-53895 PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization throug… Pimp My Log Mitigation only Fix from $2,3002025-12-16 MEDIUM 6.5 CVE-2025-65782 An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization flaw in card update handling … Wekan after 8.15 Fix from $1,6002025-12-15 MEDIUM 5.5 CVE-2025-46289 A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app m… macOS 14.8.3 / 15.7.3+ Fix from $1,6002025-12-12 MEDIUM 6.7 CVE-2025-40830 A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization c… Sinec Security Monitor 4.10.0+ Fix from $1,6002025-12-09 HIGH 7.5 CVE-2025-14206 A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/… Online Student Clearance System No fix yet Fix from $1,9502025-12-08 MEDIUM 5.3 CVE-2025-12720 The g-FFL Cockpit plugin for WordPress is vulnerable to unauthorized modification of data due to IP-based authorization that can be spoofed in the ha… Mitigation only Fix from $1,6002025-12-06 MEDIUM 5.4 CVE-2025-12505 The weDocs plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.1.14. This is due to the plugin not prop… Mitigation only Fix from $1,6002025-12-06 MEDIUM 6.3 CVE-2025-14089 A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the file /api/admin/update_account/ … Mitigation only Fix from $1,6002025-12-05 MEDIUM 6.3 CVE-2025-14088 A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of the file /je/load. This mani… No fix yet Fix from $1,6002025-12-05 HIGH 8.1 CVE-2025-14016 A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/dele… Mall Swarm after 1.0.3 Fix from $1,9502025-12-04 CRITICAL 9.8 CVE-2025-58386 In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks.… Terminalfour 8.4.1.2+ Fix from $2,3002025-12-02 CRITICAL 9.6 CVE-2025-66301 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /… Grav 1.8.0+ Fix from $2,3002025-12-01