Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.3 CVE-2025-68941 Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources. Gitea 1.22.3+ Fix from $1,6002025-12-26 MEDIUM 5.3 CVE-2025-68938 Gitea before 1.25.2 mishandles authorization for deletion of releases. Gitea 1.25.2+ Fix from $1,6002025-12-26 HIGH 8.1 CVE-2025-15085 A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/… Youlai Mall Mitigation only Fix from $1,9502025-12-25 HIGH 7.5 CVE-2025-66378 Pexip Infinity 38.0 and 38.1 before 39.0 has insufficient access control in the RTMP implementation, allowing an attacker to disconnect RTMP streams … Pexip Infinity 39.0+ Fix from $1,9502025-12-25 CRITICAL 9.1 CVE-2025-59683 Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Lega… Pexip Infinity 38.1+ Fix from $2,3002025-12-25 CRITICAL 9.8 CVE-2019-25237 V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulati… Mitigation only Fix from $2,3002025-12-24 HIGH 8.1 CVE-2018-25146 Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system proces… Ipn4g Firmware No fix yet Fix from $1,9502025-12-24 HIGH 7.2 CVE-2025-2515 A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a manag… Patch available Fix from $1,9502025-12-24 HIGH 8.2 CVE-2025-68476 KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been ide… Patch available Fix from $1,9502025-12-22 HIGH 8.1 CVE-2025-58052 Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers with… Galette 1.2.0+ Fix from $1,9502025-12-19 HIGH 7.8 CVE-2025-47382 Memory corruption while loading an invalid firmware in boot loader. Fastconnect 6200 Firmware Patch available Fix from $1,9502025-12-18 HIGH 7.5 CVE-2025-68129 Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. In applications built with the Auth0-PHP SDK, the audience validation in access … Laravel Auth0 5.5.0 / 5.6.0+ Fix from $1,9502025-12-17 HIGH 7.8 CVE-2025-14305 ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replace ListCheck.exe with a malici… Mitigation only Fix from $1,9502025-12-17 MEDIUM 5.3 CVE-2025-67740 In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata Teamcity 2025.11+ Fix from $1,6002025-12-11 MEDIUM 5.4 CVE-2025-67490 The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0… Nextjs Auth0 Patch available Fix from $1,6002025-12-10 CRITICAL 9.8 CVE-2025-13184EPSS 11% Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V… X5000r Firmware Mitigation only Fix from $2,3002025-12-10 MEDIUM 5.3 CVE-2025-9056 Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation. Audiolink Mitigation only Fix from $1,6002025-12-10 MEDIUM 6.5 CVE-2025-54838 An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGat… Fortiportal after 7.4.5 Fix from $1,6002025-12-09 MEDIUM 6.5 CVE-2025-66581 Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side aut… Learning 2.41.0+ Fix from $1,6002025-12-05 HIGH 7.4 CVE-2025-66623 Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.… Strimzi 0.49.1+ Fix from $1,9502025-12-05 MEDIUM 6.5 CVE-2025-65900 Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient permission v… Kalmia No fix yet Fix from $1,6002025-12-04 HIGH 8.1 CVE-2025-14016 A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/dele… Mall Swarm after 1.0.3 Fix from $1,9502025-12-04 MEDIUM 5.0 CVE-2025-66406 Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, there is an improper authorizati… Mitigation only Fix from $1,6002025-12-03 MEDIUM 5.4 CVE-2025-20381 In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL co… Mitigation only Fix from $1,6002025-12-03 HIGH 7.5 CVE-2024-32643 Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a… Masacms 7.2.8 / 7.3.13+ Fix from $1,9502025-12-03 HIGH 8.6 CVE-2025-13829 Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other use… Mitigation only Fix from $1,9502025-12-01 HIGH 8.1 CVE-2025-13813 A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the componen… Mogublog after 5.2 Fix from $1,9502025-12-01 CRITICAL 9.8 CVE-2025-13806 A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzbo… Nutzboot after 2.6.0 Fix from $2,3002025-12-01 HIGH 7.1 CVE-2025-66423 Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. Trytond 6.0.70 / 7.0.40+ Fix from $1,9502025-11-30 MEDIUM 6.5 CVE-2025-66424 Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70. Trytond 6.0.70 / 7.0.40+ Fix from $1,6002025-11-30