Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 5.3 CVE-2025-53532 giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauthorized user to create discuss… Patch available Fix from $1,6002025-07-07 MEDIUM 6.5 CVE-2025-6713 An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of th… MongoDB 6.0.22 / 7.0.19+ Fix from $1,6002025-07-07 HIGH 8.8 CVE-2025-53106 Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain … Graylog 6.2.4+ Fix from $1,9502025-07-02 HIGH 8.8 CVE-2025-6736 A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-… Cms No fix yet Fix from $1,9502025-06-27 HIGH 8.8 CVE-2025-6735 A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the comp… Cms No fix yet Fix from $1,9502025-06-27 MEDIUM 5.3 CVE-2025-6702 A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment… Litemall No fix yet Fix from $1,6002025-06-26 MEDIUM 6.4 CVE-2025-20264 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass… Identity Services Engine Mitigation only Fix from $1,6002025-06-25 MEDIUM 6.5 CVE-2025-6431 When a link can be opened in an external application, Firefox for Android will, by default, prompt the user before doing so. An attacker could have b… Firefox 140.0+ Fix from $1,6002025-06-24 HIGH 8.1 CVE-2025-6329 A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown process… Real Estate Management System No fix yet Fix from $1,9502025-06-20 MEDIUM 5.3 CVE-2025-6099 A vulnerability was found in szluyu99 gin-vue-blog up to 61dd11ccd296e8642a318ada3ef7b3f7776d2410. It has been declared as critical. This vulnerabili… Mitigation only Fix from $1,6002025-06-16 HIGH 8.1 CVE-2025-22239 Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the … Mitigation only Fix from $1,9502025-06-13 HIGH 8.7 CVE-2025-46840 Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalatio… Experience Manager 6.5.23.0 / 2025.5.0+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2024-43706 Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint. Kibana after 8.12.0 Fix from $1,9502025-06-10 HIGH 8.2 CVE-2025-43585 Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that cou… Commerce Mitigation only Fix from $1,9502025-06-10 HIGH 7.3 CVE-2025-5522 A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affe… Mitigation only Fix from $1,9502025-06-03 HIGH 7.5 CVE-2025-5511 A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of… Shiyi Blog after 1.2.1 Fix from $1,9502025-06-03 MEDIUM 5.0 CVE-2025-3454 This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. … Mitigation only Fix from $1,6002025-06-02 CRITICAL 9.8 CVE-2025-4631 The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versio… Mitigation only Fix from $2,3002025-05-31 HIGH 8.8 CVE-2025-4672 The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization placed on the permission_callback… Mitigation only Fix from $1,9502025-05-31 HIGH 8.8 CVE-2025-4103 The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_ajax_wpgm_start_geojson_import(… Mitigation only Fix from $1,9502025-05-31 HIGH 7.5 CVE-2025-5182 A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability a… Vacation Rental Management Platform 1.0.2+ Fix from $1,9502025-05-26 MEDIUM 5.5 CVE-2025-5175 A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the function Save of the file pypickle/p… Pypickle 2.0.0+ Fix from $1,6002025-05-26 HIGH 8.8 CVE-2025-48371 OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfga-0.2.16 through openfga-0.2.… Helm Charts 0.2.32 / 1.8.13+ Fix from $1,9502025-05-22 HIGH 8.8 CVE-2025-48063 XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part of the s… Xwiki 16.10.4+ Fix from $1,9502025-05-21 HIGH 8.8 CVE-2025-4473 The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in… Mitigation only Fix from $1,9502025-05-13 HIGH 8.8 CVE-2025-4474 The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_fun… Mitigation only Fix from $1,9502025-05-13 HIGH 7.1 CVE-2025-31249 A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An app may be able to access sensitive user data. macOS 15.5+ Fix from $1,9502025-05-12 HIGH 8.8 CVE-2025-29827 Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. Azure Automation Mitigation only Fix from $1,9502025-05-08 CRITICAL 9.8 CVE-2025-4104 The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form… Mitigation only Fix from $2,3002025-05-07 HIGH 8.2 CVE-2025-3921 The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on … Mitigation only Fix from $1,9502025-05-07