Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 5.3 CVE-2025-3924 The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access of data via its publicly exposed reset-password end… Mitigation only Fix from $1,6002025-05-07 CRITICAL 9.8 CVE-2025-3918 The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in ve… Mitigation only Fix from $2,3002025-05-03 HIGH 7.3 CVE-2025-4210 A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers… Patch available Fix from $1,9502025-05-02 MEDIUM 5.4 CVE-2025-4136 A vulnerability was found in Weitong Mall 1.0.0. It has been classified as critical. This affects an unknown part of the component Sale Endpoint. The… Mitigation only Fix from $1,6002025-04-30 CRITICAL 9.8 CVE-2025-30389 Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. Azure Ai Bot Service Mitigation only Fix from $2,3002025-04-30 HIGH 8.8 CVE-2025-30390 Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. Azure Machine Learning No fix yet Fix from $1,9502025-04-30 CRITICAL 9.8 CVE-2025-30392 Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. Azure Ai Bot Service Mitigation only Fix from $2,3002025-04-30 MEDIUM 5.3 CVE-2025-32972 XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc… Xwiki 15.10.12 / 16.4.3+ Fix from $1,6002025-04-30 CRITICAL 9.1 CVE-2025-4016 A vulnerability classified as critical has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This affects the functio… Novel Plus 5.1.1+ Fix from $2,3002025-04-28 MEDIUM 6.5 CVE-2025-4017 A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This vulnerability affects… Novel Plus after 5.1.1 Fix from $1,6002025-04-28 MEDIUM 5.3 CVE-2025-3981 A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. T… Internet Doctor Workstation System No fix yet Fix from $1,6002025-04-27 MEDIUM 5.3 CVE-2025-3980 A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. This vulnerability… Internet Doctor Workstation System No fix yet Fix from $1,6002025-04-27 MEDIUM 5.4 CVE-2025-3967 A vulnerability was found in itwanger paicoding 1.0.3. It has been classified as critical. This affects an unknown part of the file /article/api/post… Paicoding No fix yet Fix from $1,6002025-04-27 HIGH 7.5 CVE-2025-32982 NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module. Ngeniusone 6.4.0+ Fix from $1,9502025-04-25 CRITICAL 9.8 CVE-2025-29659 Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary. Xy 3820 Firmware No fix yet Fix from $2,3002025-04-21 HIGH 8.8 CVE-2025-3587 A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /ge… Studentmanager No fix yet Fix from $1,9502025-04-14 MEDIUM 6.3 CVE-2025-3569 A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this issue is some unknown functiona… Db Hospital Drug No fix yet Fix from $1,6002025-04-14 MEDIUM 6.5 CVE-2025-3564 A vulnerability classified as problematic has been found in huanfenz/code-projects StudentManager up to 1.0. This affects an unknown part of the comp… Studentmanager No fix yet Fix from $1,6002025-04-14 MEDIUM 6.5 CVE-2025-3536 A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown func… Employee Management System No fix yet Fix from $1,6002025-04-13 MEDIUM 5.3 CVE-2025-3537 A vulnerability was found in Tutorials-Website Employee Management System 1.0. It has been classified as critical. This affects an unknown part of th… Employee Management System No fix yet Fix from $1,6002025-04-13 HIGH 8.8 CVE-2025-29794 Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Sharepoint Enterprise Server 16.0.18526.20172+ Fix from $1,9502025-04-08 MEDIUM 5.3 CVE-2025-30373 Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and ha… Graylog 6.1.9+ Fix from $1,6002025-04-07 CRITICAL 9.1 CVE-2025-3202 A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoy… Ruoyi Ai 2.0.1+ Fix from $2,3002025-04-04 CRITICAL 9.8 CVE-2025-3199 A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unknown functionality of the fil… Ruoyi Ai 2.0.2+ Fix from $2,3002025-04-04 CRITICAL 9.8 CVE-2025-26683 Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. Azure Playwright Mitigation only Fix from $2,3002025-03-31 HIGH 8.3 CVE-2025-3014 Insecure Direct Object References (IDOR) in access control in Tracking 2.1.4 on NightWolf Penetration Testing allows an attacker to access via manipu… Mitigation only Fix from $1,9502025-03-31 HIGH 8.3 CVE-2025-3013 Insecure Direct Object References (IDOR) in access control in Customer Portal before 2.1.4 on NightWolf Penetration Testing allows an attacker to acc… Mitigation only Fix from $1,9502025-03-31 MEDIUM 6.8 CVE-2025-2600 Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PA… Remote Desktop Manager 2024.3.31.0 / 2025.1.26.0+ Fix from $1,6002025-03-26 HIGH 8.0 CVE-2025-29778 Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and I… Kyverno 1.13.6+ Fix from $1,9502025-03-24 MEDIUM 5.3 CVE-2025-2639 A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/relea… Jizhicms after 1.7 Fix from $1,6002025-03-23