Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Jumpserver HIGH 7.1
CVE-2025-62795

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privi…

Fix: 3.10.21 / 4.10.12+
Fix from $1,950 2025-10-30
Civictheme Design System HIGH 7.5
CVE-2025-12082

Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0…

Fix: 1.12.0+
Fix from $1,950 2025-10-30
Digital Experience Platform MEDIUM 5.4
CVE-2025-62259

Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA…

Fix: 7.4.3.110+
Fix from $1,600 2025-10-27
GitLab MEDIUM 6.5
CVE-2025-11971

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could hav…

Fix: 18.3.5 / 18.4.3+
Fix from $1,600 2025-10-27
Aws Plugin HIGH 8.1
CVE-2025-59048

OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IA…

Fix: 0.1.1+
Fix from $1,950 2025-10-23
Restaurant Brands International Assistant MEDIUM 5.8
CVE-2025-62651

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface.

Fix: after 2025-09-06
Fix from $1,600 2025-10-17
Restaurant Brands International Assistant MEDIUM 5.8
CVE-2025-62647

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to cal…

Fix: after 2025-09-06
Fix from $1,600 2025-10-17
Restaurant Brands International Assistant MEDIUM 5.8
CVE-2025-62648

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.

Fix: after 2025-09-06
Fix from $1,600 2025-10-17
Unclassified HIGH 8.6
CVE-2025-48044

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/po…

Patch available
Fix from $1,950 2025-10-17
Unclassified HIGH 8.7
CVE-2025-6892

An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mech…

Mitigation only
Fix from $1,950 2025-10-17
Unclassified HIGH 8.1
CVE-2025-62506

MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege escalation vulnerability allows…

Patch available
Fix from $1,950 2025-10-16
Enterprise Integrator MEDIUM 5.7
CVE-2025-9955

An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP ad…

Mitigation only
Fix from $1,600 2025-10-16
Api Control Plane CRITICAL 9.8
CVE-2025-10611

Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be …

Mitigation only
Fix from $2,300 2025-10-16
Commerce MEDIUM 5.9
CVE-2025-54265

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vuln…

Mitigation only
Fix from $1,600 2025-10-14
Commerce MEDIUM 6.5
CVE-2025-54267

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vuln…

Mitigation only
Fix from $1,600 2025-10-14
Commerce HIGH 8.1
CVE-2025-54263

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vuln…

Mitigation only
Fix from $1,950 2025-10-14
Digital Experience Platform MEDIUM 5.4
CVE-2025-62243

Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 20…

Fix: 7.4.3.113 / 2023.q3.9+
Fix from $1,600 2025-10-13
Powerjob HIGH 7.5
CVE-2025-11581

A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the compon…

Fix: after 5.1.2
Fix from $1,950 2025-10-10
Powerjob MEDIUM 5.3
CVE-2025-11580

A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing autho…

Fix: after 5.1.2
Fix from $1,600 2025-10-10
Unclassified HIGH 8.6
CVE-2025-48043

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/po…

Patch available
Fix from $1,950 2025-10-10
Unclassified MEDIUM 6.7
CVE-2025-8886

Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect A…

Mitigation only
Fix from $1,600 2025-10-10
Unclassified MEDIUM 5.4
CVE-2025-7374

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. Th…

Mitigation only
Fix from $1,600 2025-10-10
GitLab HIGH 7.7
CVE-2025-11340

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have all…

Fix: 18.3.4 / 18.4.2+
Fix from $1,950 2025-10-09
Opnform MEDIUM 6.3
CVE-2025-11438

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component A…

Fix: after 1.9.3
Fix from $1,600 2025-10-08
Log Server MEDIUM 6.5
CVE-2025-44824

Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/i…

Fix: 2024+
Fix from $1,600 2025-10-07
Cmc HIGH 8.1
CVE-2025-3719

An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users wi…

Fix: 25.2.0+
Fix from $1,950 2025-10-07
Opensupports MEDIUM 5.4
CVE-2025-10696

OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor …

No fix yet
Fix from $1,600 2025-10-03
Zabbix MEDIUM 6.5
CVE-2025-27236

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows d…

Fix: 6.0.41 / 7.0.17+
Fix from $1,600 2025-10-03
Unclassified HIGH 7.6
CVE-2024-58260

A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users…

Mitigation only
Fix from $1,950 2025-10-02
Unclassified HIGH 7.6
CVE-2025-41246

VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-…

Mitigation only
Fix from $1,950 2025-09-29