Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.1 CVE-2025-62795 JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privi… Jumpserver 3.10.21 / 4.10.12+ Fix from $1,9502025-10-30 HIGH 7.5 CVE-2025-12082 Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0… Civictheme Design System 1.12.0+ Fix from $1,9502025-10-30 MEDIUM 5.4 CVE-2025-62259 Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA… Digital Experience Platform 7.4.3.110+ Fix from $1,6002025-10-27 MEDIUM 6.5 CVE-2025-11971 GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could hav… GitLab 18.3.5 / 18.4.3+ Fix from $1,6002025-10-27 HIGH 8.1 CVE-2025-59048 OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is vulnerable to cross-account IA… Aws Plugin 0.1.1+ Fix from $1,9502025-10-23 MEDIUM 5.8 CVE-2025-62651 The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface. Restaurant Brands International Assistant after 2025-09-06 Fix from $1,6002025-10-17 MEDIUM 5.8 CVE-2025-62647 The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to cal… Restaurant Brands International Assistant after 2025-09-06 Fix from $1,6002025-10-17 MEDIUM 5.8 CVE-2025-62648 The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume. Restaurant Brands International Assistant after 2025-09-06 Fix from $1,6002025-10-17 HIGH 8.6 CVE-2025-48044 Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/po… Patch available Fix from $1,9502025-10-17 HIGH 8.7 CVE-2025-6892 An Incorrect Authorization vulnerability has been identified in Moxa’s network security appliances and routers. A flaw in the API authentication mech… Mitigation only Fix from $1,9502025-10-17 HIGH 8.1 CVE-2025-62506 MinIO is a high-performance object storage system. In all versions prior to RELEASE.2025-10-15T17-29-55Z, a privilege escalation vulnerability allows… Patch available Fix from $1,9502025-10-16 MEDIUM 5.7 CVE-2025-9955 An improper access control vulnerability exists in WSO2 Enterprise Integrator product due to insufficient permission restrictions on internal SOAP ad… Enterprise Integrator Mitigation only Fix from $1,6002025-10-16 CRITICAL 9.8 CVE-2025-10611 Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be … Api Control Plane Mitigation only Fix from $2,3002025-10-16 MEDIUM 5.9 CVE-2025-54265 Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vuln… Commerce Mitigation only Fix from $1,6002025-10-14 MEDIUM 6.5 CVE-2025-54267 Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vuln… Commerce Mitigation only Fix from $1,6002025-10-14 HIGH 8.1 CVE-2025-54263 Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vuln… Commerce Mitigation only Fix from $1,9502025-10-14 MEDIUM 5.4 CVE-2025-62243 Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 20… Digital Experience Platform 7.4.3.113 / 2023.q3.9+ Fix from $1,6002025-10-13 HIGH 7.5 CVE-2025-11581 A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the compon… Powerjob after 5.1.2 Fix from $1,9502025-10-10 MEDIUM 5.3 CVE-2025-11580 A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing autho… Powerjob after 5.1.2 Fix from $1,6002025-10-10 HIGH 8.6 CVE-2025-48043 Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/po… Patch available Fix from $1,9502025-10-10 MEDIUM 6.7 CVE-2025-8886 Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect A… Mitigation only Fix from $1,6002025-10-10 MEDIUM 5.4 CVE-2025-7374 The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions up to, and including, 7.6. Th… Mitigation only Fix from $1,6002025-10-10 HIGH 7.7 CVE-2025-11340 GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have all… GitLab 18.3.4 / 18.4.2+ Fix from $1,9502025-10-09 MEDIUM 6.3 CVE-2025-11438 A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component A… Opnform after 1.9.3 Fix from $1,6002025-10-08 MEDIUM 6.5 CVE-2025-44824 Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/i… Log Server 2024+ Fix from $1,6002025-10-07 HIGH 8.1 CVE-2025-3719 An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users wi… Cmc 25.2.0+ Fix from $1,9502025-10-07 MEDIUM 5.4 CVE-2025-10696 OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor … Opensupports No fix yet Fix from $1,6002025-10-03 MEDIUM 6.5 CVE-2025-27236 A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows d… Zabbix 6.0.41 / 7.0.17+ Fix from $1,6002025-10-03 HIGH 7.6 CVE-2024-58260 A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users… Mitigation only Fix from $1,9502025-10-02 HIGH 7.6 CVE-2025-41246 VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-… Mitigation only Fix from $1,9502025-09-29