Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.0 CVE-2025-55205 Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows… Patch available Fix from $2,3002025-08-18 HIGH 8.8 CVE-2025-36120 IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect autho… Storage Virtualize 8.4.0.18 / 8.5.0.16+ Fix from $1,9502025-08-18 HIGH 8.8 CVE-2025-7773 A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number increments at an interval that… Mitigation only Fix from $1,9502025-08-14 MEDIUM 6.5 CVE-2024-10219 An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under ce… GitLab 18.0.6 / 18.1.4+ Fix from $1,6002025-08-13 HIGH 7.5 CVE-2025-49556 Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vuln… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502025-08-12 HIGH 8.0 CVE-2024-41979 A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < … Opcenter Quality Mitigation only Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-42951 Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the c… Mitigation only Fix from $1,9502025-08-12 HIGH 8.8 CVE-2025-8807 A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tia… Tianti after 2.3 Fix from $1,9502025-08-10 MEDIUM 5.4 CVE-2025-8796 A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file … Litmus after 3.19.0 Fix from $1,6002025-08-10 HIGH 8.7 CVE-2025-54888 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5… Patch available Fix from $1,9502025-08-09 HIGH 7.4 CVE-2025-55077 Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating system commands within the rem… Erp Pro 9 Mitigation only Fix from $1,9502025-08-07 MEDIUM 6.9 CVE-2025-8533 A vulnerability was identified in the XPC services of Fantastical. The services failed to implement proper client authorization checks in its listene… Mitigation only Fix from $1,6002025-08-07 CRITICAL 10.0 CVE-2025-54253 KEVEPSS 88% Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. … Experience Manager Forms after 6.5.23.0 Fix from $2,3002025-08-05 MEDIUM 5.3 CVE-2025-54554 tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQ… Mitigation only Fix from $1,6002025-08-04 HIGH 8.8 CVE-2025-20701EPSS 7% In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation … Mitigation only Fix from $1,9502025-08-04 HIGH 7.3 CVE-2025-8435 A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown… Online Movie Streaming No fix yet Fix from $1,9502025-08-01 HIGH 7.3 CVE-2025-8434 A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the fil… Online Movie Streaming No fix yet Fix from $1,9502025-08-01 MEDIUM 6.5 CVE-2025-54583 GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push… Gitproxy 1.19.2+ Fix from $1,6002025-07-30 MEDIUM 5.5 CVE-2025-43251 An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.6. A local attacker may gain access to K… macOS 15.6+ Fix from $1,6002025-07-30 HIGH 7.8 CVE-2025-6018 A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw all… Pam Config No fix yet Fix from $1,9502025-07-23 CRITICAL 9.4 CVE-2025-29757 An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account t… Mitigation only Fix from $2,3002025-07-19 HIGH 8.7 CVE-2025-53943 VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler wh… Mitigation only Fix from $1,9502025-07-16 MEDIUM 5.5 CVE-2025-50085 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 an… MySQL after 9.3.0 Fix from $1,6002025-07-15 MEDIUM 6.1 CVE-2025-30748 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are af… Peoplesoft Enterprise Peopletools Patch available Fix from $1,6002025-07-15 HIGH 8.8 CVE-2025-30751 Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.27 and 23.4-23.8. Easily exp… Database Server after 23.8 Fix from $1,9502025-07-15 MEDIUM 5.5 CVE-2025-30739 Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affect… Crm Technical Foundation after 12.2.13 Fix from $1,6002025-07-15 HIGH 8.1 CVE-2025-30743 Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations). The supported version… Lease And Finance Management Patch available Fix from $1,9502025-07-15 HIGH 8.1 CVE-2025-30744 Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Errors). Supported versions that … Mobile Field Service after 12.2.13 Fix from $1,9502025-07-15 HIGH 8.8 CVE-2025-53895 ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulne… Zitadel 2.70.14 / 2.71.13+ Fix from $1,9502025-07-15 HIGH 8.8 CVE-2025-53836 XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502025-07-15