Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Fabric Composer MEDIUM 6.5
CVE-2025-23053

A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation co…

Fix: 7.1.1+
Fix from $1,600 2025-01-28
Debian Linux CRITICAL 9.9
CVE-2025-0781

An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating…

Fix: after 2020.3.19
Fix from $2,300 2025-01-28
macOS MEDIUM 5.5
CVE-2025-24114

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3.…

Fix: 13.7.3 / 14.7.3+
Fix from $1,600 2025-01-27
Ipados CRITICAL 9.1
CVE-2024-54530

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visionOS 2.2, watchOS 11.2. Passwo…

Fix: 2.2 / 11.2+
Fix from $2,300 2025-01-27
Ipados MEDIUM 5.3
CVE-2024-54488

A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS So…

Fix: 13.7.2 / 14.7.2+
Fix from $1,600 2025-01-27
Ipados CRITICAL 9.1
CVE-2024-54512

The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A system binary could be used …

Fix: 11.2 / 18.2+
Fix from $2,300 2025-01-27
Common Licensing MEDIUM 6.5
CVE-2023-50946

IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken author…

Mitigation only
Fix from $1,600 2025-01-26
Folder Based Authorization Strategy MEDIUM 6.8
CVE-2025-24401

Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabl…

Fix: after 217.vd5b_18537403e
Fix from $1,600 2025-01-22
Unclassified MEDIUM 6.4
CVE-2024-42013

In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attacker with Windows administrati…

Mitigation only
Fix from $1,600 2025-01-22
Argus Safety MEDIUM 6.1
CVE-2025-21570

Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login). The supported version tha…

Mitigation only
Fix from $1,600 2025-01-21
Agile Product Lifecycle Management HIGH 7.5
CVE-2025-21565

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.…

Mitigation only
Fix from $1,950 2025-01-21
Hyperion Data Relationship Management MEDIUM 6.6
CVE-2025-21569

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). The supported version that …

Mitigation only
Fix from $1,600 2025-01-21
Communications Order And Service Management MEDIUM 5.3
CVE-2025-21554

Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Support…

Mitigation only
Fix from $1,600 2025-01-21
Mysql Server MEDIUM 5.5
CVE-2025-21555

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and …

Fix: after 9.1.0
Fix from $1,600 2025-01-21
Agile Product Lifecycle Management CRITICAL 9.9
CVE-2025-21556

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that …

Mitigation only
Fix from $2,300 2025-01-21
Application Express MEDIUM 5.4
CVE-2025-21557

Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulner…

Mitigation only
Fix from $1,600 2025-01-21
Primavera P6 Enterprise Project Portfolio Management MEDIUM 5.4
CVE-2025-21558

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Su…

Fix: after 21.12.20.0
Fix from $1,600 2025-01-21
Agile Product Lifecycle Management MEDIUM 6.5
CVE-2025-21560

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported version tha…

Mitigation only
Fix from $1,600 2025-01-21
Peoplesoft Enterprise Scm Purchasing MEDIUM 5.4
CVE-2025-21561

Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affec…

Mitigation only
Fix from $1,600 2025-01-21
Peoplesoft Enterprise Fin Esettlements MEDIUM 5.4
CVE-2025-21539

Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is a…

Mitigation only
Fix from $1,600 2025-01-21
Mysql Server MEDIUM 5.4
CVE-2025-21540

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40…

Fix: after 9.1.0
Fix from $1,600 2025-01-21
Vm Virtualbox MEDIUM 5.5
CVE-2025-21533

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.24 / 7.1.6+
Fix from $1,600 2025-01-21
Peoplesoft Enterprise Fin Cash Management MEDIUM 5.4
CVE-2025-21537

Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management). The supported version tha…

Mitigation only
Fix from $1,600 2025-01-21
E Business Suite HIGH 8.1
CVE-2025-21516

Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported versions that are affected are…

Fix: after 12.2.13
Fix from $1,950 2025-01-21
E Business Suite HIGH 8.1
CVE-2025-21506

Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation). Supported versions that are af…

Fix: after 12.2.13
Fix from $1,950 2025-01-21
Unclassified MEDIUM 6.4
CVE-2024-51417

An issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection types and static properties/fields.

Mitigation only
Fix from $1,600 2025-01-21
Unclassified MEDIUM 5.6
CVE-2025-0580

A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of …

Mitigation only
Fix from $1,600 2025-01-20
Wegia CRITICAL 9.8
CVE-2024-57032

WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so …

Fix: 3.2.0+
Fix from $2,300 2025-01-17
Foiaxpress Public Access Link CRITICAL 9.1
CVE-2024-53553

An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.

No fix yet
Fix from $2,300 2025-01-16
Dir 816 Firmware MEDIUM 6.5
CVE-2024-57677

An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan servi…

Mitigation only
Fix from $1,600 2025-01-16