Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Powerscale Onefs HIGH 7.0
CVE-2025-26330

Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local a…

Fix: after 9.10.1.1
Fix from $1,950 2025-04-10
Web T MEDIUM 6.5
CVE-2025-3475

Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoo…

Fix: 1.1.0+
Fix from $1,600 2025-04-09
Unclassified HIGH 7.5
CVE-2025-31481

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured secu…

Patch available
Fix from $1,950 2025-04-03
Unclassified CRITICAL 9.1
CVE-2024-38392

Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the ap…

Mitigation only
Fix from $2,300 2025-04-02
macOS CRITICAL 9.8
CVE-2025-24233

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
Ipados HIGH 7.5
CVE-2025-24221

This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, visionOS 2.4. Sensiti…

Fix: 2.4 / 17.7.6+
Fix from $1,950 2025-03-31
Tuleap MEDIUM 5.3
CVE-2025-30209

Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or info…

Fix: 16.4-10 / 16.5-6+
Fix from $1,600 2025-03-31
Htcondor HIGH 8.1
CVE-2025-30093

HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass auth…

Fix: 23.0.22 / 23.10.22+
Fix from $1,950 2025-03-27
GitLab HIGH 8.8
CVE-2025-2242

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 1…

Fix: 17.8.6 / 17.9.3+
Fix from $1,950 2025-03-27
Appsmith MEDIUM 6.5
CVE-2024-55965

An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (spe…

Fix: 1.51+
Fix from $1,600 2025-03-26
Next.js CRITICAL 9.1
CVE-2025-29927EPSS 99%

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and …

Fix: 12.3.5 / 13.5.9+
Fix from $2,300 2025-03-21
Mattermost Server MEDIUM 6.5
CVE-2025-30179

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attac…

Fix: 9.11.9 / 10.3.4+
Fix from $1,600 2025-03-21
Mattermost Server HIGH 8.8
CVE-2025-25274

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authen…

Fix: 9.11.9 / 10.3.4+
Fix from $1,950 2025-03-21
macOS HIGH 7.8
CVE-2024-44305

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges.

Fix: 14.6+
Fix from $1,950 2025-03-21
Infocad CRITICAL 9.8
CVE-2025-26853

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

Fix: 3.5.2.0+
Fix from $2,300 2025-03-20
Chuanhuchatgpt MEDIUM 6.5
CVE-2024-9159

An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the s…

No fix yet
Fix from $1,600 2025-03-20
Lunary MEDIUM 6.1
CVE-2024-9098

In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, …

Fix: 1.4.30+
Fix from $1,600 2025-03-20
Open Webui MEDIUM 6.7
CVE-2024-7039

In open-webui/open-webui version v0.3.8, there is an improper privilege management vulnerability. The application allows an attacker, acting as an ad…

No fix yet
Fix from $1,600 2025-03-20
Lunary HIGH 7.3
CVE-2024-10275

In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change…

Fix: 1.5.7+
Fix from $1,950 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-10273

In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The …

Fix: 1.5.7+
Fix from $1,600 2025-03-20
Anythingllm HIGH 8.3
CVE-2024-10109

A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "…

Fix: 1.3.1+
Fix from $1,950 2025-03-20
Xwiki HIGH 7.5
CVE-2025-29924

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private informatio…

Fix: 15.10.14 / 16.4.6+
Fix from $1,950 2025-03-19
Unclassified MEDIUM 6.9
CVE-2025-2202

Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to …

Mitigation only
Fix from $1,600 2025-03-17
Unclassified MEDIUM 6.9
CVE-2025-2201

Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive in…

Mitigation only
Fix from $1,600 2025-03-17
Unclassified HIGH 7.8
CVE-2025-30074

Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation ro…

Mitigation only
Fix from $1,950 2025-03-16
Dataease CRITICAL 9.8
CVE-2025-27138

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the i…

Fix: 2.10.6+
Fix from $2,300 2025-03-13
Unclassified HIGH 8.2
CVE-2025-29997

This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated remote a…

Mitigation only
Fix from $1,950 2025-03-13
GitLab MEDIUM 6.5
CVE-2025-0652

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, …

Fix: 17.7.7 / 17.8.5+
Fix from $1,600 2025-03-13
Umbraco Cms MEDIUM 6.4
CVE-2025-27602

Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1…

Fix: 10.8.9 / 13.7.1+
Fix from $1,600 2025-03-11
Fortisandbox HIGH 7.8
CVE-2024-45328

An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated …

Fix: 4.4.7+
Fix from $1,950 2025-03-11