Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Unclassified HIGH 7.5
CVE-2025-27822

An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily switch to another user account. T…

Mitigation only
Fix from $1,950 2025-03-07
Devolutions Server HIGH 7.1
CVE-2025-2003

Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.

Fix: 2024.3.13.0+
Fix from $1,950 2025-03-05
Vasion Print CRITICAL 9.8
CVE-2025-27645

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extension Installation by Trusting …

Fix: 20.0.2368 / 22.0.933+
Fix from $2,300 2025-03-05
Axis Os MEDIUM 5.5
CVE-2025-0359

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed…

Fix: 11.11.135 / 12.2.52+
Fix from $1,600 2025-03-04
Axis Os HIGH 7.8
CVE-2025-0360

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th…

Fix: 11.11.135 / 12.2.41+
Fix from $1,950 2025-03-04
Api Manager MEDIUM 5.6
CVE-2024-2321

An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token inst…

Mitigation only
Fix from $1,600 2025-02-27
Moodle MEDIUM 6.5
CVE-2025-26526

Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.

Fix: 4.1.16 / 4.3.10+
Fix from $1,600 2025-02-24
Moodle MEDIUM 5.3
CVE-2025-26531

Insufficient capability checks made it possible to disable badges a user does not have permission to access.

Fix: 4.1.16 / 4.3.10+
Fix from $1,600 2025-02-24
Unclassified HIGH 8.8
CVE-2024-5705

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the c…

Mitigation only
Fix from $1,950 2025-02-19
Cognos Controller MEDIUM 6.5
CVE-2024-45081

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to i…

Fix: 11.0.1.4+
Fix from $1,600 2025-02-19
Unclassified MEDIUM 6.8
CVE-2024-39328

Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a…

Mitigation only
Fix from $1,600 2025-02-18
Unclassified HIGH 8.8
CVE-2025-26511

Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through…

Patch available
Fix from $1,950 2025-02-13
Nomad HIGH 7.1
CVE-2025-0937

Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other na…

Fix: 1.7.18 / 1.8.10+
Fix from $1,950 2025-02-12
Maxair HIGH 8.8
CVE-2025-1214

A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of th…

No fix yet
Fix from $1,950 2025-02-12
Unclassified MEDIUM 6.8
CVE-2024-54916

An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate priv…

Mitigation only
Fix from $1,600 2025-02-11
Commerce CRITICAL 9.1
CVE-2025-24434EPSS 17%

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability th…

Mitigation only
Fix from $2,300 2025-02-11
Commerce MEDIUM 5.4
CVE-2025-24437

Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability th…

Mitigation only
Fix from $1,600 2025-02-11
Commerce B2b HIGH 7.1
CVE-2025-24407

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability th…

Fix: 1.3.3+
Fix from $1,950 2025-02-11
Commerce HIGH 8.2
CVE-2025-24409

Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability t…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2025-02-11
Ipados MEDIUM 6.1
CVE-2025-24200 KEV

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7…

Fix: 15.8.4 / 16.7.11+
Fix from $1,600 2025-02-10
Unclassified MEDIUM 5.3
CVE-2021-41528

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentia…

Mitigation only
Fix from $1,600 2025-02-07
Cassandra MEDIUM 5.4
CVE-2025-24860

Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when usi…

Fix: 4.0.16 / 4.1.8+
Fix from $1,600 2025-02-04
Mall Tiny HIGH 8.8
CVE-2024-57434

macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super adminis…

No fix yet
Fix from $1,950 2025-01-31
Dmh Wt7600nex Firmware HIGH 7.3
CVE-2024-23929

This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although a…

Mitigation only
Fix from $1,950 2025-01-31
Unclassified HIGH 8.7
CVE-2025-24500

The vulnerability allows an unauthenticated attacker to access information in PAM database.

No fix yet
Fix from $1,950 2025-01-30
macOS MEDIUM 5.1
CVE-2025-24099

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker …

Fix: 13.7.3 / 14.7.3+
Fix from $1,600 2025-01-30
Ruoyi MEDIUM 5.4
CVE-2024-57438

Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.

No fix yet
Fix from $1,600 2025-01-29
Manageengine Applications Manager MEDIUM 6.5
CVE-2024-41140

Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

Fix: 17.0 / 17.3+
Fix from $1,600 2025-01-29
Unclassified HIGH 8.6
CVE-2025-24479

A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and all…

Mitigation only
Fix from $1,950 2025-01-28
Fabric Composer MEDIUM 6.5
CVE-2025-23054

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator use…

Fix: 7.1.1+
Fix from $1,600 2025-01-28