Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified MEDIUM 5.7
CVE-2025-11060

A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthor…

Patch available
Fix from $1,600 2025-09-26
Omni MEDIUM 5.4
CVE-2025-59824

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escap…

Fix: 0.48.0+
Fix from $1,600 2025-09-24
Authlib HIGH 7.5
CVE-2025-59420

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that dec…

Fix: 1.6.4+
Fix from $1,950 2025-09-22
Unclassified HIGH 8.8
CVE-2025-10016

The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can reque…

Mitigation only
Fix from $1,950 2025-09-16
Safari MEDIUM 5.4
CVE-2025-31254

This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web con…

Fix: 26.0+
Fix from $1,600 2025-09-15
Mcp Kubernetes Server MEDIUM 5.3
CVE-2025-59376

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g.,…

Fix: after 0.1.11
Fix from $1,600 2025-09-15
Digital Experience Platform MEDIUM 5.3
CVE-2025-43789

JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi …

Fix: 7.4.3.120 / 2024.Q1.10+
Fix from $1,600 2025-09-12
Digital Experience Platform MEDIUM 6.5
CVE-2025-43784

Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024…

Fix: 7.4.3.125 / 2024.Q1.13+
Fix from $1,600 2025-09-10
Experience Manager MEDIUM 6.5
CVE-2025-54246

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security featu…

Fix: after 2025.8.0
Fix from $1,600 2025-09-09
Unclassified HIGH 7.1
CVE-2025-48042

Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability …

Patch available
Fix from $1,950 2025-09-07
Android HIGH 7.8
CVE-2025-48523

In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could le…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-32333

In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to lo…

Patch available
Fix from $1,950 2025-09-04
Android MEDIUM 5.5
CVE-2025-26442

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic…

Patch available
Fix from $1,600 2025-09-04
Android HIGH 7.8
CVE-2025-26436

In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due t…

Patch available
Fix from $1,950 2025-09-04
Unclassified MEDIUM 6.3
CVE-2025-23262

NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modi…

Mitigation only
Fix from $1,600 2025-09-04
Unclassified HIGH 8.7
CVE-2025-23256

NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to mod…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-22428

In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the pr…

Mitigation only
Fix from $1,950 2025-09-02
Rocket.chat HIGH 7.5
CVE-2025-7974

rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio…

Fix: 7.4.4 / 7.5.3+
Fix from $1,950 2025-09-02
Unclassified MEDIUM 6.9
CVE-2025-41030

Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain information from other users via GET …

Mitigation only
Fix from $1,600 2025-09-02
Unclassified MEDIUM 6.9
CVE-2025-41031

Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other users' profile pictures via a P…

Mitigation only
Fix from $1,600 2025-09-02
Digital Experience Platform HIGH 7.2
CVE-2025-3586

In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10…

Fix: 7.4.3.43+
Fix from $1,950 2025-09-01
Tuleap MEDIUM 5.3
CVE-2025-54877

Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions befor…

Fix: 16.9-8 / 16.10-5+
Fix from $1,600 2025-08-29
Whatsapp MEDIUM 5.4
CVE-2025-55177 KEV

Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, a…

Fix: 2.25.21.73 / 2.25.21.78+
Fix from $1,600 2025-08-29
Rockoa MEDIUM 6.5
CVE-2025-9602

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation result…

Fix: after 2.6.9
Fix from $1,600 2025-08-29
Kibana MEDIUM 6.5
CVE-2025-25010

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access a…

Fix: 9.0.6 / 9.1.3+
Fix from $1,600 2025-08-28
Unclassified MEDIUM 6.5
CVE-2025-9376

The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data …

Mitigation only
Fix from $1,600 2025-08-28
Unclassified MEDIUM 6.7
CVE-2025-5187

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object…

Mitigation only
Fix from $1,600 2025-08-27
Jazz Foundation CRITICAL 9.1
CVE-2025-36157

IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to upda…

Patch available
Fix from $2,300 2025-08-24
Intellij Idea MEDIUM 6.5
CVE-2025-57728

In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files

Fix: 2025.2+
Fix from $1,600 2025-08-20
Helm Charts CRITICAL 9.8
CVE-2025-55213

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1…

Fix: 0.2.42 / 1.9.5+
Fix from $2,300 2025-08-18