Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Coldfusion CRITICAL 9.1
CVE-2025-43561EPSS 21%

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code…

Mitigation only
Fix from $2,300 2025-05-13
Centreon Web HIGH 7.2
CVE-2025-4646

Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.0…

Fix: 24.04.10 / 24.10.4+
Fix from $1,950 2025-05-13
Superset HIGH 8.8
CVE-2025-27696

Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read…

Fix: 4.1.2+
Fix from $1,950 2025-05-13
macOS MEDIUM 5.5
CVE-2025-30440

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be abl…

Fix: 13.7.6 / 14.7.6+
Fix from $1,600 2025-05-12
Azure Automation HIGH 8.8
CVE-2025-29827

Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2025-05-08
Znuny HIGH 7.5
CVE-2025-26842

An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to use…

Fix: after 7.1.3
Fix from $1,950 2025-05-08
F5os A HIGH 8.8
CVE-2025-46265

On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher priv…

Fix: after 1.6.2
Fix from $1,950 2025-05-07
F5os A HIGH 8.1
CVE-2025-36546

On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance …

Fix: 1.5.3+
Fix from $1,950 2025-05-07
Unclassified MEDIUM 6.7
CVE-2025-3272

Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager.  The vulnerability could allow authenticated users to change their pas…

Mitigation only
Fix from $1,600 2025-05-07
Unclassified CRITICAL 9.4
CVE-2025-3476

Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated us…

Mitigation only
Fix from $2,300 2025-05-07
Unclassified MEDIUM 5.3
CVE-2025-3609

The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to t…

Mitigation only
Fix from $1,600 2025-05-06
Vault HIGH 8.8
CVE-2025-3879

Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the poten…

Fix: 1.16.18 / 1.17.14+
Fix from $1,950 2025-05-02
Unclassified HIGH 7.4
CVE-2025-46569

Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API …

Patch available
Fix from $1,950 2025-05-01
Unclassified HIGH 7.8
CVE-2025-23244

NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an unprivileged attacker to escalate permissions. A successful exploit…

Mitigation only
Fix from $1,950 2025-05-01
Bookgy HIGH 7.5
CVE-2025-40619

Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without…

Mitigation only
Fix from $1,950 2025-04-29
Books Management System CRITICAL 9.8
CVE-2025-3963

A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processin…

No fix yet
Fix from $2,300 2025-04-27
Books Management System CRITICAL 9.8
CVE-2025-3960

A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionali…

No fix yet
Fix from $2,300 2025-04-27
Unclassified MEDIUM 5.4
CVE-2025-3861

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misc…

Mitigation only
Fix from $1,600 2025-04-25
Sherpa Orchestrator MEDIUM 6.5
CVE-2025-46544

In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.

Mitigation only
Fix from $1,600 2025-04-25
Unclassified MEDIUM 5.4
CVE-2024-10306

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the for…

Patch available
Fix from $1,600 2025-04-23
Unclassified HIGH 8.1
CVE-2025-43922

The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.

Mitigation only
Fix from $1,950 2025-04-21
Unclassified MEDIUM 5.5
CVE-2024-12862

Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to r…

Mitigation only
Fix from $1,600 2025-04-21
Unclassified MEDIUM 6.1
CVE-2025-3838

An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the cust…

Mitigation only
Fix from $1,600 2025-04-21
Mailman MEDIUM 5.3
CVE-2025-43921

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple…

Fix: after 2.1.39
Fix from $1,600 2025-04-20
Unclassified HIGH 8.2
CVE-2025-43917

In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifica…

Mitigation only
Fix from $1,950 2025-04-19
Dify MEDIUM 6.5
CVE-2025-32796

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enabl…

Fix: after 0.6.8
Fix from $1,600 2025-04-18
Sterling Connect Direct Web Services MEDIUM 6.5
CVE-2024-49808

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to impro…

Fix: 6.1.0.28 / 6.2.0.27+
Fix from $1,600 2025-04-18
Unclassified MEDIUM 5.3
CVE-2025-3453

The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and mor…

Mitigation only
Fix from $1,600 2025-04-17
Crm Technical Foundation MEDIUM 6.1
CVE-2025-21582

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affect…

Fix: after 12.2.14
Fix from $1,600 2025-04-15
Unclassified MEDIUM 5.4
CVE-2025-32068

Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawi…

Mitigation only
Fix from $1,600 2025-04-11