Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.5 CVE-2025-10978 A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /sys/user/exportXls of the comp… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-25 MEDIUM 6.5 CVE-2025-10979 A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulati… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-25 MEDIUM 5.3 CVE-2025-10977 A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteBatch. The manipulation of the… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-25 MEDIUM 5.3 CVE-2025-10976 A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/getDepartUserList. Executing man… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-25 MEDIUM 5.3 CVE-2025-10947 A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of the file /api/areacliente/pe… Mitigation only Fix from $1,6002025-09-25 HIGH 7.6 CVE-2025-59305 Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control… Langfuse 3.109.0+ Fix from $1,9502025-09-24 MEDIUM 6.8 CVE-2025-57438 The 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be accessible only afte… Ip 4c Firmware No fix yet Fix from $1,6002025-09-22 MEDIUM 5.3 CVE-2025-10759 A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula… Qloapps after 1.7.0 Fix from $1,6002025-09-21 MEDIUM 6.4 CVE-2025-8532 Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workfl… Mitigation only Fix from $1,6002025-09-19 HIGH 8.8 CVE-2025-10707 A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing m… Jeecg Boot after 3.8.2 Fix from $1,9502025-09-19 MEDIUM 6.5 CVE-2025-8057 Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Improper Authorization vulnerabili… Mitigation only Fix from $1,6002025-09-16 HIGH 7.5 CVE-2025-41249 The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized sup… Mitigation only Fix from $1,9502025-09-16 MEDIUM 5.5 CVE-2025-43231 A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8. An app may be able to access user-sensitive data. macOS 14.8+ Fix from $1,6002025-09-15 CRITICAL 9.8 CVE-2025-31255 An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14… Ipados 14.8 / 15.7+ Fix from $2,3002025-09-15 HIGH 8.8 CVE-2025-10390 A weakness has been identified in CRMEB up to 5.6.1. The affected element is the function editAddress of the file app/services/user/UserAddressServic… Crmeb after 5.6.1 Fix from $1,9502025-09-14 HIGH 8.8 CVE-2025-10389 A security flaw has been discovered in CRMEB up to 5.6.1. Impacted is the function Save of the file app/services/system/admin/SystemAdminServices.php… Crmeb after 5.6.1 Fix from $1,9502025-09-14 MEDIUM 5.4 CVE-2025-10384 A flaw has been found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the file /system/role/authUse… Ruoyi after 4.8.1 Fix from $1,6002025-09-13 HIGH 7.3 CVE-2025-10374 A security flaw has been discovered in Shenzhen Sixun Business Management System 7/11. This affects an unknown part of the file /Adm/OperatorStop. Pe… No fix yet Fix from $1,9502025-09-13 MEDIUM 6.5 CVE-2025-10319 A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog … Jeecg Boot after 3.8.2 Fix from $1,6002025-09-12 HIGH 8.8 CVE-2025-10318 A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSo… Jeecg Boot after 3.8.2 Fix from $1,9502025-09-12 HIGH 8.8 CVE-2025-10291 A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. … Litemall after 1.8.0 Fix from $1,9502025-09-12 HIGH 8.8 CVE-2025-10278 A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of … Ruoyi Vue Pro after 2025.09 Fix from $1,9502025-09-12 HIGH 8.8 CVE-2025-10276 A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/t… Ruoyi Vue Pro after 2025.09 Fix from $1,9502025-09-12 HIGH 8.8 CVE-2025-10277 A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file /crm/receivable/submit. The … Yudao Cloud after 2025.09 Fix from $1,9502025-09-12 HIGH 8.8 CVE-2025-10275 A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Executing manipu… Yudao Cloud after 2025.09 Fix from $1,9502025-09-12 MEDIUM 5.4 CVE-2025-10209 A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Ha… Mitigation only Fix from $1,6002025-09-10 MEDIUM 6.3 CVE-2025-10086 A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the c… Platform No fix yet Fix from $1,6002025-09-08 HIGH 7.8 CVE-2025-26430 In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to loca… Android Patch available Fix from $1,9502025-09-04 MEDIUM 5.4 CVE-2025-9937 A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulat… Mitigation only Fix from $1,6002025-09-04 HIGH 8.8 CVE-2025-9760 A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Mat… I Educar after 2.10.0 Fix from $1,9502025-09-01