Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Gitea MEDIUM 5.3
CVE-2025-68941

Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

Fix: 1.22.3+
Fix from $1,600 2025-12-26
Gitea MEDIUM 5.3
CVE-2025-68938

Gitea before 1.25.2 mishandles authorization for deletion of releases.

Fix: 1.25.2+
Fix from $1,600 2025-12-26
Youlai Mall HIGH 8.1
CVE-2025-15085

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/…

Mitigation only
Fix from $1,950 2025-12-25
Pexip Infinity HIGH 7.5
CVE-2025-66378

Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams …

Fix: 39.0+
Fix from $1,950 2025-12-25
Pexip Infinity CRITICAL 9.1
CVE-2025-59683

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Lega…

Fix: 38.1+
Fix from $2,300 2025-12-25
Unclassified CRITICAL 9.8
CVE-2019-25237

V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulati…

Mitigation only
Fix from $2,300 2025-12-24
Ipn4g Firmware HIGH 8.1
CVE-2018-25146

Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system proces…

No fix yet
Fix from $1,950 2025-12-24
Unclassified HIGH 7.2
CVE-2025-2515

A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a manag…

Patch available
Fix from $1,950 2025-12-24
Unclassified HIGH 8.2
CVE-2025-68476

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been ide…

Patch available
Fix from $1,950 2025-12-22
Galette HIGH 8.1
CVE-2025-58052

Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with…

Fix: 1.2.0+
Fix from $1,950 2025-12-19
Fastconnect 6200 Firmware HIGH 7.8
CVE-2025-47382

Memory corruption while loading an invalid firmware in boot loader.

Patch available
Fix from $1,950 2025-12-18
Laravel Auth0 HIGH 7.5
CVE-2025-68129

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access …

Fix: 5.5.0 / 5.6.0+
Fix from $1,950 2025-12-17
Unclassified HIGH 7.8
CVE-2025-14305

ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malici…

Mitigation only
Fix from $1,950 2025-12-17
Teamcity MEDIUM 5.3
CVE-2025-67740

In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata

Fix: 2025.11+
Fix from $1,600 2025-12-11
Nextjs Auth0 MEDIUM 5.4
CVE-2025-67490

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0…

Patch available
Fix from $1,600 2025-12-10
X5000r Firmware CRITICAL 9.8
CVE-2025-13184EPSS 11%

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V…

Mitigation only
Fix from $2,300 2025-12-10
Audiolink MEDIUM 5.3
CVE-2025-9056

Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation.

Mitigation only
Fix from $1,600 2025-12-10
Fortiportal MEDIUM 6.5
CVE-2025-54838

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGat…

Fix: after 7.4.5
Fix from $1,600 2025-12-09
Learning MEDIUM 6.5
CVE-2025-66581

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side aut…

Fix: 2.41.0+
Fix from $1,600 2025-12-05
Strimzi HIGH 7.4
CVE-2025-66623

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.…

Fix: 0.49.1+
Fix from $1,950 2025-12-05
Kalmia MEDIUM 6.5
CVE-2025-65900

Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission v…

No fix yet
Fix from $1,600 2025-12-04
Mall Swarm HIGH 8.1
CVE-2025-14016

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/dele…

Fix: after 1.0.3
Fix from $1,950 2025-12-04
Unclassified MEDIUM 5.0
CVE-2025-66406

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorizati…

Mitigation only
Fix from $1,600 2025-12-03
Unclassified MEDIUM 5.4
CVE-2025-20381

In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL co…

Mitigation only
Fix from $1,600 2025-12-03
Masacms HIGH 7.5
CVE-2024-32643

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a…

Fix: 7.2.8 / 7.3.13+
Fix from $1,950 2025-12-03
Unclassified HIGH 8.6
CVE-2025-13829

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other use…

Mitigation only
Fix from $1,950 2025-12-01
Mogublog HIGH 8.1
CVE-2025-13813

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the componen…

Fix: after 5.2
Fix from $1,950 2025-12-01
Nutzboot CRITICAL 9.8
CVE-2025-13806

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzbo…

Fix: after 2.6.0
Fix from $2,300 2025-12-01
Trytond HIGH 7.1
CVE-2025-66423

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Fix: 6.0.70 / 7.0.40+
Fix from $1,950 2025-11-30
Trytond MEDIUM 6.5
CVE-2025-66424

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

Fix: 6.0.70 / 7.0.40+
Fix from $1,600 2025-11-30