Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 5.7 CVE-2025-11060 A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthor… Patch available Fix from $1,6002025-09-26 MEDIUM 5.4 CVE-2025-59824 Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escap… Omni 0.48.0+ Fix from $1,6002025-09-24 HIGH 7.5 CVE-2025-59420 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that dec… Authlib 1.6.4+ Fix from $1,9502025-09-22 HIGH 8.8 CVE-2025-10016 The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unprivileged attacker can reque… Mitigation only Fix from $1,9502025-09-16 MEDIUM 5.4 CVE-2025-31254 This issue was addressed with improved URL validation. This issue is fixed in Safari 26, iOS 26 and iPadOS 26. Processing maliciously crafted web con… Safari 26.0+ Fix from $1,6002025-09-15 MEDIUM 5.3 CVE-2025-59376 feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g.,… Mcp Kubernetes Server after 0.1.11 Fix from $1,6002025-09-15 MEDIUM 5.3 CVE-2025-43789 JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi … Digital Experience Platform 7.4.3.120 / 2024.Q1.10+ Fix from $1,6002025-09-12 MEDIUM 6.5 CVE-2025-43784 Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024… Digital Experience Platform 7.4.3.125 / 2024.Q1.13+ Fix from $1,6002025-09-10 MEDIUM 6.5 CVE-2025-54246 Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security featu… Experience Manager after 2025.8.0 Fix from $1,6002025-09-09 HIGH 7.1 CVE-2025-48042 Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability … Patch available Fix from $1,9502025-09-07 HIGH 7.8 CVE-2025-48523 In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could le… Android Patch available Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-32333 In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to lo… Android Patch available Fix from $1,9502025-09-04 MEDIUM 5.5 CVE-2025-26442 In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic… Android Patch available Fix from $1,6002025-09-04 HIGH 7.8 CVE-2025-26436 In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due t… Android Patch available Fix from $1,9502025-09-04 MEDIUM 6.3 CVE-2025-23262 NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modi… Mitigation only Fix from $1,6002025-09-04 HIGH 8.7 CVE-2025-23256 NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to mod… Mitigation only Fix from $1,9502025-09-04 HIGH 7.8 CVE-2025-22428 In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the pr… Android Mitigation only Fix from $1,9502025-09-02 HIGH 7.5 CVE-2025-7974 rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio… Rocket.chat 7.4.4 / 7.5.3+ Fix from $1,9502025-09-02 MEDIUM 6.9 CVE-2025-41030 Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to obtain information from other users via GET … Mitigation only Fix from $1,6002025-09-02 MEDIUM 6.9 CVE-2025-41031 Lack of authorisation in Deporsite by T-INNOVA. This vulnerability allows an unauthenticated attacker to change other users' profile pictures via a P… Mitigation only Fix from $1,6002025-09-02 HIGH 7.2 CVE-2025-3586 In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10… Digital Experience Platform 7.4.3.43+ Fix from $1,9502025-09-01 MEDIUM 5.3 CVE-2025-54877 Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions befor… Tuleap 16.9-8 / 16.10-5+ Fix from $1,6002025-08-29 MEDIUM 5.4 CVE-2025-55177 KEV Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, a… Whatsapp 2.25.21.73 / 2.25.21.78+ Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-9602 A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation result… Rockoa after 2.6.9 Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-25010 Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access a… Kibana 9.0.6 / 9.1.3+ Fix from $1,6002025-08-28 MEDIUM 6.5 CVE-2025-9376 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to unauthorized access of data … Mitigation only Fix from $1,6002025-08-28 MEDIUM 6.7 CVE-2025-5187 A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object… Mitigation only Fix from $1,6002025-08-27 CRITICAL 9.1 CVE-2025-36157 IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to upda… Jazz Foundation Patch available Fix from $2,3002025-08-24 MEDIUM 6.5 CVE-2025-57728 In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files Intellij Idea 2025.2+ Fix from $1,6002025-08-20 CRITICAL 9.8 CVE-2025-55213 OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.9.3 to v1… Helm Charts 0.2.42 / 1.9.5+ Fix from $2,3002025-08-18