Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 8.8 CVE-2025-9687 A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoA… I Educar after 2.10 Fix from $1,9502025-08-30 HIGH 8.8 CVE-2025-9609 A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulati… I Educar after 2.10 Fix from $1,9502025-08-29 MEDIUM 6.5 CVE-2025-9602 A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation result… Rockoa after 2.6.9 Fix from $1,6002025-08-29 CRITICAL 9.8 CVE-2025-53795 Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. Pc Manager Mitigation only Fix from $2,3002025-08-21 MEDIUM 6.3 CVE-2025-9151 A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the function updateJsonValueByName of … No fix yet Fix from $1,6002025-08-19 CRITICAL 9.8 CVE-2025-7778 The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within… Mitigation only Fix from $2,3002025-08-15 MEDIUM 6.5 CVE-2025-55675 Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated use… Superset 5.0.0+ Fix from $1,6002025-08-14 MEDIUM 5.4 CVE-2025-8840 A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoi… Jsherp No fix yet Fix from $1,6002025-08-11 HIGH 8.8 CVE-2025-8839 A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endp… Jsherp No fix yet Fix from $1,9502025-08-11 HIGH 7.8 CVE-2025-8794 A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown funct… Litmus after 3.19.0 Fix from $1,9502025-08-10 MEDIUM 6.3 CVE-2025-8791 A vulnerability was found in LitmusChaos Litmus up to 3.19.0. It has been rated as critical. This issue affects some unknown processing of the file /… Litmus after 3.19.0 Fix from $1,6002025-08-10 HIGH 8.8 CVE-2025-8756 A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preH… Tduck Platform after 5.1 Fix from $1,9502025-08-09 MEDIUM 5.3 CVE-2025-8755 A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberC… Mall after 1.0.3 Fix from $1,6002025-08-09 CRITICAL 9.1 CVE-2025-53792 Azure Portal Elevation of Privilege Vulnerability Azure Portal No fix yet Fix from $2,3002025-08-07 MEDIUM 5.3 CVE-2025-8547 A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email … Pybbs after 6.0.0 Fix from $1,6002025-08-05 HIGH 7.5 CVE-2025-54868 LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chat… Librechat 0.7.8+ Fix from $1,9502025-08-05 CRITICAL 9.8 CVE-2025-54130 Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If… Cursor 1.3.9+ Fix from $2,3002025-08-05 MEDIUM 6.5 CVE-2025-54585 GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attackers can exploit the way GitP… Gitproxy 1.19.2+ Fix from $1,6002025-07-30 HIGH 7.7 CVE-2025-53944 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external A… Autogpt Platform Patch available Fix from $1,9502025-07-30 CRITICAL 9.8 CVE-2025-8261 A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the componen… Vaelsys Mitigation only Fix from $2,3002025-07-28 HIGH 8.3 CVE-2025-54378 HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcms-nodejs and versions 11.0.8 … Haxcms Nodejs 11.0.9 / 11.0.14+ Fix from $1,9502025-07-26 HIGH 8.1 CVE-2025-7947 A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component … Jsherp after 3.5 Fix from $1,9502025-07-22 HIGH 8.8 CVE-2025-49746 Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. Azure Machine Learning Mitigation only Fix from $1,9502025-07-18 MEDIUM 5.4 CVE-2025-46732 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnerability in… Opencti 6.6.6+ Fix from $1,6002025-07-18 MEDIUM 6.1 CVE-2025-50073 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are… Weblogic Server Patch available Fix from $1,6002025-07-15 HIGH 8.7 CVE-2024-26291 An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path … Mitigation only Fix from $1,9502025-07-14 MEDIUM 5.4 CVE-2025-53709 Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The service only installed on a s… Mitigation only Fix from $1,6002025-07-10 HIGH 8.8 CVE-2025-0928 In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the c… Juju 2.9.52 / 3.6.8+ Fix from $1,9502025-07-08 MEDIUM 6.5 CVE-2025-53512 The /log endpoint on a Juju controller lacked sufficient authorization checks, allowing unauthorized users to access debug messages that could contai… Juju 2.9.52 / 3.6.8+ Fix from $1,6002025-07-08 HIGH 8.8 CVE-2025-49701 Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Server 16.0.18526.20424+ Fix from $1,9502025-07-08