Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 8.8 CVE-2025-13808 A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerability is the function update of … Orion Ops after 2025-08-01 Fix from $1,9502025-12-01 CRITICAL 9.8 CVE-2025-13806 A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzbo… Nutzboot after 2.6.0 Fix from $2,3002025-12-01 HIGH 8.1 CVE-2025-65966 OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a dir… Oneuptime No fix yet Fix from $1,9502025-11-26 MEDIUM 5.4 CVE-2025-65963 Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow n… Patch available Fix from $1,6002025-11-26 CRITICAL 9.8 CVE-2025-64063 Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can e… Project Contract Management Mitigation only Fix from $2,3002025-11-25 HIGH 8.8 CVE-2025-64065 The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or us… Project Contract Management Mitigation only Fix from $1,9502025-11-25 HIGH 8.8 CVE-2025-64062 The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the aut… Project Contract Management Mitigation only Fix from $1,9502025-11-25 HIGH 8.8 CVE-2025-13576 A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulat… Blog Site Mitigation only Fix from $1,9502025-11-24 MEDIUM 6.5 CVE-2025-65107 Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in… Langfuse 2.95.12 / 3.131.0+ Fix from $1,6002025-11-21 HIGH 8.8 CVE-2025-64751 OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.4.0 to v1… Helm Charts 0.2.49 / 1.11.1+ Fix from $1,9502025-11-21 CRITICAL 9.8 CVE-2025-64655 Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. Dynamics Omnichannel Sdk Storage Containers No fix yet Fix from $2,3002025-11-20 HIGH 8.8 CVE-2025-65094 WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their privileges to the Administrator… Wbce Cms 1.6.4+ Fix from $1,9502025-11-19 HIGH 8.1 CVE-2025-65033 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any a… Rallly 4.5.4+ Fix from $1,9502025-11-19 MEDIUM 6.5 CVE-2025-65028 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a… Rallly 4.5.4+ Fix from $1,6002025-11-19 HIGH 8.1 CVE-2025-65029 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a… Rallly 4.5.4+ Fix from $1,9502025-11-19 HIGH 7.1 CVE-2025-65030 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment deletion API allows any auth… Rallly 4.5.4+ Fix from $1,9502025-11-19 MEDIUM 6.5 CVE-2025-65031 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in the comment creation endpoint a… Rallly 4.5.4+ Fix from $1,6002025-11-19 MEDIUM 6.5 CVE-2025-65020 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability in the p… Rallly 4.5.4+ Fix from $1,6002025-11-19 CRITICAL 9.1 CVE-2025-65021 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists i… Rallly 4.5.4+ Fix from $2,3002025-11-19 CRITICAL 9.8 CVE-2025-63218 The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missing authenticat… Wolf1ms Firmware after 1.0.3 Fix from $2,3002025-11-19 MEDIUM 5.3 CVE-2025-12814 The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect capability check on the sites… Mitigation only Fix from $1,6002025-11-19 MEDIUM 5.3 CVE-2025-12777 The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to… Mitigation only Fix from $1,6002025-11-19 MEDIUM 5.3 CVE-2025-13117 A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability is the function cancelOrder … Mall after 1.0.3 Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-13114 A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /cart/update/attr. Such manipul… Mall Swarm after 1.0.3 Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-13115 A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the… Mall after 1.0.3 Fix from $1,6002025-11-13 MEDIUM 5.3 CVE-2025-13116 A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserO… Mall after 1.0.3 Fix from $1,6002025-11-13 HIGH 8.8 CVE-2025-64523 File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Ve… Filebrowser 2.45.1+ Fix from $1,9502025-11-12 HIGH 8.1 CVE-2025-11521 The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of rem… Mitigation only Fix from $1,9502025-11-11 MEDIUM 5.4 CVE-2025-12435 Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HT… Chrome 142.0.7444.59+ Fix from $1,6002025-11-10 CRITICAL 9.6 CVE-2025-63691 In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/… Pig after 3.8.2 Fix from $2,3002025-11-07