Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Multipass HIGH 7.8
CVE-2025-5199

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by mo…

Fix: 1.16.0+
Fix from $1,950 2025-07-12
Junos MEDIUM 6.5
CVE-2025-6549

An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attack…

Fix: 21.4+
Fix from $1,600 2025-07-11
Coldfusion HIGH 7.3
CVE-2025-49536

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security fea…

Mitigation only
Fix from $1,950 2025-07-08
Ar8035 Firmware CRITICAL 9.1
CVE-2025-21450

Cryptographic issue occurs due to use of insecure connection method while downloading.

No fix yet
Fix from $2,300 2025-07-08
Unclassified CRITICAL 9.3
CVE-2025-26850

The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on manage…

Mitigation only
Fix from $2,300 2025-07-05
Sudo HIGH 8.8
CVE-2025-32462

Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute co…

Fix: 1.9.17+
Fix from $1,950 2025-06-30
Mattermost Server MEDIUM 5.4
CVE-2025-46702

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member…

Fix: 9.11.16 / 10.5.6+
Fix from $1,600 2025-06-30
Mattermost Server MEDIUM 5.4
CVE-2025-47871

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membe…

Fix: 9.11.16 / 10.5.6+
Fix from $1,600 2025-06-30
Unclassified CRITICAL 9.3
CVE-2025-53391

The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_a…

Patch available
Fix from $2,300 2025-06-28
Litemall MEDIUM 5.3
CVE-2025-6702

A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment…

No fix yet
Fix from $1,600 2025-06-26
MongoDB MEDIUM 5.4
CVE-2025-6707

Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administra…

Fix: 5.0.31 / 6.0.24+
Fix from $1,600 2025-06-26
Maxicharger Ac Elite Business C50 Firmware HIGH 8.8
CVE-2025-5822

Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote a…

Fix: 1.39.51 / 1.56.51+
Fix from $1,950 2025-06-25
Unclassified HIGH 8.1
CVE-2025-52890

Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates n…

Patch available
Fix from $1,950 2025-06-25
Wise 4060lan Firmware HIGH 8.1
CVE-2025-48466

Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs…

No fix yet
Fix from $1,950 2025-06-24
Unclassified MEDIUM 5.0
CVE-2025-52918

Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.

Mitigation only
Fix from $1,600 2025-06-21
Dotnetnuke HIGH 7.5
CVE-2025-52487

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN…

Fix: 10.0.1+
Fix from $1,950 2025-06-21
Ai Engine HIGH 8.8
CVE-2025-5071

The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow…

Fix: 2.8.4+
Fix from $1,950 2025-06-19
Unclassified CRITICAL 9.8
CVE-2025-49825EPSS 8%

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 …

Mitigation only
Fix from $2,300 2025-06-17
Xwiki HIGH 8.8
CVE-2025-49586

XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all us…

Fix: 16.4.7 / 16.10.3+
Fix from $1,950 2025-06-13
Unclassified MEDIUM 5.3
CVE-2025-6003

The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in…

Mitigation only
Fix from $1,600 2025-06-12
Commerce Eurobank \(redirect\) HIGH 8.8
CVE-2025-48445

Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redire…

Fix: 2.1.1+
Fix from $1,950 2025-06-11
Commerce Alphabank Redirect HIGH 8.8
CVE-2025-48446

Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirec…

Fix: 1.0.3+
Fix from $1,950 2025-06-11
Unclassified HIGH 7.8
CVE-2024-7457

The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the…

Mitigation only
Fix from $1,950 2025-06-11
Unclassified MEDIUM 5.5
CVE-2024-8270

The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling t…

Mitigation only
Fix from $1,600 2025-06-11
Wyse Management Suite MEDIUM 6.8
CVE-2025-36578

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access…

Fix: 5.2+
Fix from $1,600 2025-06-10
Unclassified MEDIUM 6.5
CVE-2025-40567

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions <…

Mitigation only
Fix from $1,600 2025-06-10
Gim MEDIUM 6.5
CVE-2025-40668

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of …

Mitigation only
Fix from $1,600 2025-06-09
Gim MEDIUM 6.5
CVE-2025-40669

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each o…

Mitigation only
Fix from $1,600 2025-06-09
Gim HIGH 8.8
CVE-2025-40670

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many priv…

Mitigation only
Fix from $1,950 2025-06-09
Deno CRITICAL 9.1
CVE-2025-48935

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's per…

Fix: 2.2.5+
Fix from $2,300 2025-06-04