Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Siem HIGH 8.8
CVE-2025-66360

An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) …

Fix: 7.7.0+
Fix from $1,950 2025-11-28
Unclassified CRITICAL 9.2
CVE-2024-5539

The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass …

Mitigation only
Fix from $2,300 2025-11-27
Youlai Boot CRITICAL 9.8
CVE-2025-55469

Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

Mitigation only
Fix from $2,300 2025-11-26
Lunary HIGH 8.8
CVE-2025-9803

lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application …

Patch available
Fix from $1,950 2025-11-25
Soplanning HIGH 8.8
CVE-2025-62730

SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users.…

Fix: 1.55.00+
Fix from $1,950 2025-11-20
Alumni Management System HIGH 8.1
CVE-2025-13468

A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comm…

No fix yet
Fix from $1,950 2025-11-20
Windu Cms MEDIUM 6.5
CVE-2025-59111

Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET request which allows privileged use…

Mitigation only
Fix from $1,600 2025-11-18
Winplus CRITICAL 9.8
CVE-2025-41346

Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing thei…

Mitigation only
Fix from $2,300 2025-11-18
Unclassified HIGH 7.5
CVE-2025-65073

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone au…

Mitigation only
Fix from $1,950 2025-11-17
GitLab MEDIUM 5.3
CVE-2025-11865

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under cert…

Fix: 18.3.6 / 18.4.4+
Fix from $1,600 2025-11-15
Unclassified MEDIUM 6.0
CVE-2025-12149

In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered fro…

Mitigation only
Fix from $1,600 2025-11-14
Grist Core MEDIUM 6.5
CVE-2025-64753

grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints l…

Fix: 1.7.7+
Fix from $1,600 2025-11-13
Directus MEDIUM 5.4
CVE-2025-64746

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-…

Fix: 11.13.0+
Fix from $1,600 2025-11-13
Learning MEDIUM 5.4
CVE-2025-64707

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins rev…

Fix: 2.41.0+
Fix from $1,600 2025-11-12
Unclassified HIGH 7.3
CVE-2025-13063

A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. Th…

Mitigation only
Fix from $1,950 2025-11-12
Unclassified HIGH 7.5
CVE-2025-65002

Fujitsu / Fsas Technologies iRMC S6 on M5 before 1.37S mishandles Redfish/WebUI access if the length of a username is exactly 16 characters.

Mitigation only
Fix from $1,950 2025-11-12
Pass Authentication HIGH 7.1
CVE-2025-61830

Adobe Pass versions 3.7.3 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypa…

Fix: 3.8.0+
Fix from $1,950 2025-11-11
Unclassified HIGH 8.4
CVE-2025-11862

A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API.

Mitigation only
Fix from $1,950 2025-11-11
Itop MEDIUM 6.5
CVE-2025-49145

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (most…

Fix: 2.7.13 / 3.2.2+
Fix from $1,600 2025-11-10
Forest MEDIUM 6.5
CVE-2025-12924

A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the fi…

Fix: after 2025-09-07
Fix from $1,600 2025-11-10
Forest CRITICAL 9.8
CVE-2025-12925

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/…

Fix: after 2025-09-04
Fix from $2,300 2025-11-10
Unclassified MEDIUM 5.3
CVE-2025-12621

The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured c…

Mitigation only
Fix from $1,600 2025-11-08
Suitecrm HIGH 8.3
CVE-2025-64490

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 thr…

Fix: 7.14.8 / 8.9.1+
Fix from $1,950 2025-11-08
Elastic Cloud Enterprise HIGH 8.8
CVE-2025-37736

Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be…

Fix: 3.8.3 / 4.0.3+
Fix from $1,950 2025-11-07
Forest MEDIUM 6.5
CVE-2025-63687

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/sec…

Fix: after 2025-09-04
Fix from $1,600 2025-11-07
macOS MEDIUM 5.5
CVE-2025-43397

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04
macOS HIGH 7.8
CVE-2025-43387

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. A malicious app may be…

Fix: 15.7.2+
Fix from $1,950 2025-11-04
Digital Experience Platform MEDIUM 5.3
CVE-2025-62275

Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023…

Fix: 7.4.3.112+
Fix from $1,600 2025-11-01
Log Server MEDIUM 6.5
CVE-2025-34273

Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global …

Fix: 2024+
Fix from $1,600 2025-10-30
Log Server HIGH 8.1
CVE-2023-7322

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevert…

Fix: 2024+
Fix from $1,950 2025-10-30