Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified CRITICAL 9.0
CVE-2025-55205

Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows…

Patch available
Fix from $2,300 2025-08-18
Storage Virtualize HIGH 8.8
CVE-2025-36120

IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect autho…

Fix: 8.4.0.18 / 8.5.0.16+
Fix from $1,950 2025-08-18
Unclassified HIGH 8.8
CVE-2025-7773

A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number increments at an interval that…

Mitigation only
Fix from $1,950 2025-08-14
GitLab MEDIUM 6.5
CVE-2024-10219

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under ce…

Fix: 18.0.6 / 18.1.4+
Fix from $1,600 2025-08-13
Commerce HIGH 7.5
CVE-2025-49556

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vuln…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2025-08-12
Opcenter Quality HIGH 8.0
CVE-2024-41979

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < …

Mitigation only
Fix from $1,950 2025-08-12
Unclassified HIGH 8.8
CVE-2025-42951

Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the c…

Mitigation only
Fix from $1,950 2025-08-12
Tianti HIGH 8.8
CVE-2025-8807

A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tia…

Fix: after 2.3
Fix from $1,950 2025-08-10
Litmus MEDIUM 5.4
CVE-2025-8796

A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file …

Fix: after 3.19.0
Fix from $1,600 2025-08-10
Unclassified HIGH 8.7
CVE-2025-54888

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5…

Patch available
Fix from $1,950 2025-08-09
Erp Pro 9 HIGH 7.4
CVE-2025-55077

Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the rem…

Mitigation only
Fix from $1,950 2025-08-07
Unclassified MEDIUM 6.9
CVE-2025-8533

A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listene…

Mitigation only
Fix from $1,600 2025-08-07
Experience Manager Forms CRITICAL 10.0
CVE-2025-54253 KEVEPSS 88%

Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. …

Fix: after 6.5.23.0
Fix from $2,300 2025-08-05
Unclassified MEDIUM 5.3
CVE-2025-54554

tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQ…

Mitigation only
Fix from $1,600 2025-08-04
Unclassified HIGH 8.8
CVE-2025-20701EPSS 7%

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation …

Mitigation only
Fix from $1,950 2025-08-04
Online Movie Streaming HIGH 7.3
CVE-2025-8435

A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown…

No fix yet
Fix from $1,950 2025-08-01
Online Movie Streaming HIGH 7.3
CVE-2025-8434

A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the fil…

No fix yet
Fix from $1,950 2025-08-01
Gitproxy MEDIUM 6.5
CVE-2025-54583

GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push…

Fix: 1.19.2+
Fix from $1,600 2025-07-30
macOS MEDIUM 5.5
CVE-2025-43251

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.6. A local attacker may gain access to K…

Fix: 15.6+
Fix from $1,600 2025-07-30
Pam Config HIGH 7.8
CVE-2025-6018

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw all…

No fix yet
Fix from $1,950 2025-07-23
Unclassified CRITICAL 9.4
CVE-2025-29757

An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account t…

Mitigation only
Fix from $2,300 2025-07-19
Unclassified HIGH 8.7
CVE-2025-53943

VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler wh…

Mitigation only
Fix from $1,950 2025-07-16
MySQL MEDIUM 5.5
CVE-2025-50085

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 an…

Fix: after 9.3.0
Fix from $1,600 2025-07-15
Peoplesoft Enterprise Peopletools MEDIUM 6.1
CVE-2025-30748

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are af…

Patch available
Fix from $1,600 2025-07-15
Database Server HIGH 8.8
CVE-2025-30751

Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.27 and 23.4-23.8. Easily exp…

Fix: after 23.8
Fix from $1,950 2025-07-15
Crm Technical Foundation MEDIUM 5.5
CVE-2025-30739

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affect…

Fix: after 12.2.13
Fix from $1,600 2025-07-15
Lease And Finance Management HIGH 8.1
CVE-2025-30743

Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). The supported version…

Patch available
Fix from $1,950 2025-07-15
Mobile Field Service HIGH 8.1
CVE-2025-30744

Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Errors). Supported versions that …

Fix: after 12.2.13
Fix from $1,950 2025-07-15
Zitadel HIGH 8.8
CVE-2025-53895

ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulne…

Fix: 2.70.14 / 2.71.13+
Fix from $1,950 2025-07-15
Xwiki HIGH 8.8
CVE-2025-53836

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2025-07-15