Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 8.8 CVE-2025-66360 An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) … Siem 7.7.0+ Fix from $1,9502025-11-28 CRITICAL 9.2 CVE-2024-5539 The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass … Mitigation only Fix from $2,3002025-11-27 CRITICAL 9.8 CVE-2025-55469 Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend. Youlai Boot Mitigation only Fix from $2,3002025-11-26 HIGH 8.8 CVE-2025-9803 lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application … Lunary Patch available Fix from $1,9502025-11-25 HIGH 8.8 CVE-2025-62730 SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users.… Soplanning 1.55.00+ Fix from $1,9502025-11-20 HIGH 8.1 CVE-2025-13468 A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comm… Alumni Management System No fix yet Fix from $1,9502025-11-20 MEDIUM 6.5 CVE-2025-59111 Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET request which allows privileged use… Windu Cms Mitigation only Fix from $1,6002025-11-18 CRITICAL 9.8 CVE-2025-41346 Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing thei… Winplus Mitigation only Fix from $2,3002025-11-18 HIGH 7.5 CVE-2025-65073 OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone au… Mitigation only Fix from $1,9502025-11-17 MEDIUM 5.3 CVE-2025-11865 An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under cert… GitLab 18.3.6 / 18.4.4+ Fix from $1,6002025-11-15 MEDIUM 6.0 CVE-2025-12149 In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered fro… Mitigation only Fix from $1,6002025-11-14 MEDIUM 6.5 CVE-2025-64753 grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints l… Grist Core 1.7.7+ Fix from $1,6002025-11-13 MEDIUM 5.4 CVE-2025-64746 Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-… Directus 11.13.0+ Fix from $1,6002025-11-13 MEDIUM 5.4 CVE-2025-64707 Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins rev… Learning 2.41.0+ Fix from $1,6002025-11-12 HIGH 7.3 CVE-2025-13063 A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead to missing authorization. Th… Mitigation only Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-65002 Fujitsu / Fsas Technologies iRMC S6 on M5 before 1.37S mishandles Redfish/WebUI access if the length of a username is exactly 16 characters. Mitigation only Fix from $1,9502025-11-12 HIGH 7.1 CVE-2025-61830 Adobe Pass versions 3.7.3 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypa… Pass Authentication 3.8.0+ Fix from $1,9502025-11-11 HIGH 8.4 CVE-2025-11862 A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API. Mitigation only Fix from $1,9502025-11-11 MEDIUM 6.5 CVE-2025-49145 Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (most… Itop 2.7.13 / 3.2.2+ Fix from $1,6002025-11-10 MEDIUM 6.5 CVE-2025-12924 A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the fi… Forest after 2025-09-07 Fix from $1,6002025-11-10 CRITICAL 9.8 CVE-2025-12925 A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/… Forest after 2025-09-04 Fix from $2,3002025-11-10 MEDIUM 5.3 CVE-2025-12621 The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured c… Mitigation only Fix from $1,6002025-11-08 HIGH 8.3 CVE-2025-64490 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 thr… Suitecrm 7.14.8 / 8.9.1+ Fix from $1,9502025-11-08 HIGH 8.8 CVE-2025-37736 Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be… Elastic Cloud Enterprise 3.8.3 / 4.0.3+ Fix from $1,9502025-11-07 MEDIUM 6.5 CVE-2025-63687 An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/sec… Forest after 2025-09-04 Fix from $1,6002025-11-07 MEDIUM 5.5 CVE-2025-43397 A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1… macOS 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04 HIGH 7.8 CVE-2025-43387 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. A malicious app may be… macOS 15.7.2+ Fix from $1,9502025-11-04 MEDIUM 5.3 CVE-2025-62275 Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023… Digital Experience Platform 7.4.3.112+ Fix from $1,6002025-11-01 MEDIUM 6.5 CVE-2025-34273 Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global … Log Server 2024+ Fix from $1,6002025-10-30 HIGH 8.1 CVE-2023-7322 Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevert… Log Server 2024+ Fix from $1,9502025-10-30