Vulnerability index

Browse CVEs

1,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
HIGH 7.2 CVE-2025-20125EPSS 17% A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information… Identity Services Engine 3.1+ Fix from $1,9502025-02-05 MEDIUM 6.5 CVE-2025-24376 kubewarden-controller is a Kubernetes controller that allows you to dynamically register Kubewarden admission policies. By design, AdmissionPolicy an… Patch available Fix from $1,6002025-01-30 HIGH 8.1 CVE-2024-13646 The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient… Single User Chat after 0.5 Fix from $1,9502025-01-30 HIGH 7.5 CVE-2024-13694 The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direc… Woocommerce Wishlist 1.8.8+ Fix from $1,9502025-01-30 HIGH 8.1 CVE-2025-0849 A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-… School Management Software No fix yet Fix from $1,9502025-01-30 MEDIUM 5.6 CVE-2025-0580 A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of … Mitigation only Fix from $1,6002025-01-20 HIGH 8.7 CVE-2024-55954 OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Adm… Mitigation only Fix from $1,9502025-01-16 HIGH 7.5 CVE-2025-0484 A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown processing of the file /fladmin… Native Php Cms No fix yet Fix from $1,9502025-01-15 HIGH 7.5 CVE-2025-23042 Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Py… Gradio 5.6.0+ Fix from $1,9502025-01-14 HIGH 7.2 CVE-2025-21348 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Server 16.0.17928.20356+ Fix from $1,9502025-01-14 HIGH 7.8 CVE-2025-21275 Windows App Package Installer Elevation of Privilege Vulnerability Windows 10 21h2 10.0.19044.5371 / 10.0.19045.5371+ Fix from $1,9502025-01-14 CRITICAL 9.8 CVE-2024-56323 OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19, docker v1.3.8 to v.1.8.2) a… Helm Charts 0.2.19 / 1.8.3+ Fix from $2,3002025-01-13 CRITICAL 9.1 CVE-2024-13241 Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.… Open Social 12.0.5+ Fix from $2,3002025-01-09 HIGH 8.8 CVE-2025-21611 tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd i… Tgstation Server 6.12.3+ Fix from $1,9502025-01-06 HIGH 8.8 CVE-2024-56320 GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of acce… Gocd 24.5.0+ Fix from $1,9502025-01-03 MEDIUM 5.3 CVE-2024-13109 A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue a… Yunfan Learning Examination System No fix yet Fix from $1,6002025-01-02 HIGH 8.7 CVE-2024-56802 Tapir is a private Terraform registry. Tapir versions 0.9.0 and 0.9.1 are facing a critical issue with scope-able Deploykeys where attackers can gues… Patch available Fix from $1,9502024-12-31 MEDIUM 6.8 CVE-2020-9081 There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to expl… Mate 20 Firmware 10.1.0.88 / 10.1.0.160+ Fix from $1,6002024-12-27 HIGH 8.8 CVE-2024-45387EPSS 42% An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", … Traffic Control 8.0.2+ Fix from $1,9502024-12-23 MEDIUM 5.3 CVE-2024-12901 A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api… Foxcms after 1.2 Fix from $1,6002024-12-23 HIGH 7.5 CVE-2024-56335 vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable… Vaultwarden 1.32.7+ Fix from $1,9502024-12-20 HIGH 7.3 CVE-2024-12782 A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. Thi… Mitigation only Fix from $1,9502024-12-19 MEDIUM 5.3 CVE-2024-11768 The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on… Download Manager 3.3.04+ Fix from $1,6002024-12-19 HIGH 7.5 CVE-2024-51479 Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in m… Next.js 14.2.15+ Fix from $1,9502024-12-17 MEDIUM 5.9 CVE-2024-12483 A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the comp… Ujcms 9.6.3+ Fix from $1,6002024-12-12 MEDIUM 6.5 CVE-2024-43729 Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature … Experience Manager 6.5.22.0 / 2024.11.0+ Fix from $1,6002024-12-10 MEDIUM 5.3 CVE-2024-12347 A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown pr… Jeewms Mitigation only Fix from $1,6002024-12-09 MEDIUM 6.5 CVE-2024-11860 A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects an unknown part of the … Best House Rental Management System No fix yet Fix from $1,6002024-11-27 HIGH 8.8 CVE-2024-36467 An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is en… Zabbix 5.0.43 / 6.0.33+ Fix from $1,9502024-11-27 HIGH 7.4 CVE-2024-8676 A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it d… Mitigation only Fix from $1,9502024-11-26