Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Gim MEDIUM 6.5
CVE-2025-40668

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of …

Mitigation only
Fix from $1,600 2025-06-09
Gim MEDIUM 6.5
CVE-2025-40669

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each o…

Mitigation only
Fix from $1,600 2025-06-09
Gim HIGH 8.8
CVE-2025-40670

Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many priv…

Mitigation only
Fix from $1,950 2025-06-09
Deno CRITICAL 9.1
CVE-2025-48935

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's per…

Fix: 2.2.5+
Fix from $2,300 2025-06-04
Deno MEDIUM 5.3
CVE-2025-48888

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2.13, and 2.3.2, `deno run --al…

Fix: 2.1.13 / 2.2.13+
Fix from $1,600 2025-06-04
Aqt1000 Firmware HIGH 8.6
CVE-2025-21479 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

No fix yet
Fix from $1,950 2025-06-03
Aqt1000 Firmware HIGH 8.6
CVE-2025-21480 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

Mitigation only
Fix from $1,950 2025-06-03
Unclassified HIGH 8.3
CVE-2025-3260

A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vu…

Mitigation only
Fix from $1,950 2025-06-02
Openwrt CRITICAL 9.8
CVE-2025-20674

In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of priv…

Fix: after 7.6.7.2
Fix from $2,300 2025-06-02
Navidrome MEDIUM 6.5
CVE-2025-48948

Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any aut…

Fix: 0.56.0+
Fix from $1,600 2025-05-30
Api Manager MEDIUM 5.4
CVE-2024-7096

A privilege escalation vulnerability exists in multiple WSO2 products due to a business logic flaw in SOAP admin services. A malicious actor can crea…

Mitigation only
Fix from $1,600 2025-05-30
Unclassified HIGH 8.3
CVE-2025-48881

Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12.0.0.RELEASE to 12.12.0.RELEA…

Patch available
Fix from $1,950 2025-05-30
Unclassified CRITICAL 9.3
CVE-2025-48757

An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrar…

Mitigation only
Fix from $2,300 2025-05-30
Freescout HIGH 8.1
CVE-2025-48475

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a check on which "clients" of the…

Fix: 1.8.180+
Fix from $1,950 2025-05-29
Freescout HIGH 8.1
CVE-2025-48474

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly checks user access rights for con…

Fix: 1.8.180+
Fix from $1,950 2025-05-29
Freescout HIGH 8.1
CVE-2025-48472

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that the user is disabling notifi…

Fix: 1.8.179+
Fix from $1,950 2025-05-29
Forticlient HIGH 7.8
CVE-2025-25251

An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a loca…

Fix: 7.2.9 / 7.4.3+
Fix from $1,950 2025-05-28
Schule School Management System CRITICAL 9.1
CVE-2025-48373

Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different p…

Patch available
Fix from $2,300 2025-05-22
Api Manager CRITICAL 9.8
CVE-2024-6914

An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin ser…

Mitigation only
Fix from $2,300 2025-05-22
Unclassified MEDIUM 6.0
CVE-2024-13947

Device commissioning parameters in ASPECT may be modified by an external source if administrative credentials become compromisedThis issue affects AS…

Mitigation only
Fix from $1,600 2025-05-22
Unclassified CRITICAL 9.0
CVE-2025-30171

System File Deletion vulnerabilities in ASPECT provide attackers access to delete system files if session administrator credentials become compromise…

Mitigation only
Fix from $2,300 2025-05-22
Secure Network Analytics MEDIUM 6.5
CVE-2025-20257

A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authe…

Mitigation only
Fix from $1,600 2025-05-21
Unclassified MEDIUM 5.1
CVE-2025-1418

A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/pro…

Mitigation only
Fix from $1,600 2025-05-21
Unclassified HIGH 7.0
CVE-2025-1416

In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities restricted by the MDM (Mobile De…

Mitigation only
Fix from $1,950 2025-05-21
Unclassified MEDIUM 5.1
CVE-2025-1415

A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Device Management), as well as d…

Mitigation only
Fix from $1,600 2025-05-21
TYPO3 MEDIUM 5.3
CVE-2025-47937

TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 …

Fix: 9.5.51 / 10.4.50+
Fix from $1,600 2025-05-20
Zulip MEDIUM 5.3
CVE-2025-47930

Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access contro…

Fix: 10.3+
Fix from $1,600 2025-05-16
Unclassified MEDIUM 6.6
CVE-2025-46834

Alchemy's Modular Account is a smart contract account that is compatible with ERC-4337 and ERC-6900. In versions on the 2.x branch prior to commit 5e…

Patch available
Fix from $1,600 2025-05-15
Coldfusion CRITICAL 9.1
CVE-2025-43564EPSS 15%

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file…

Mitigation only
Fix from $2,300 2025-05-13
Coldfusion HIGH 8.4
CVE-2025-43565EPSS 16%

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary code e…

Mitigation only
Fix from $1,950 2025-05-13