Vulnerability index

Browse CVEs

2,839 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.8 CVE-2025-5199 In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by mo… Multipass 1.16.0+ Fix from $1,9502025-07-12 MEDIUM 6.5 CVE-2025-6549 An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attack… Junos 21.4+ Fix from $1,6002025-07-11 HIGH 7.3 CVE-2025-49536 ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security fea… Coldfusion Mitigation only Fix from $1,9502025-07-08 CRITICAL 9.1 CVE-2025-21450 Cryptographic issue occurs due to use of insecure connection method while downloading. Ar8035 Firmware No fix yet Fix from $2,3002025-07-08 CRITICAL 9.3 CVE-2025-26850 The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on manage… Mitigation only Fix from $2,3002025-07-05 HIGH 8.8 CVE-2025-32462 Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to execute co… Sudo 1.9.17+ Fix from $1,9502025-06-30 MEDIUM 5.4 CVE-2025-46702 Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member… Mattermost Server 9.11.16 / 10.5.6+ Fix from $1,6002025-06-30 MEDIUM 5.4 CVE-2025-47871 Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membe… Mattermost Server 9.11.16 / 10.5.6+ Fix from $1,6002025-06-30 CRITICAL 9.3 CVE-2025-53391 The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_a… Patch available Fix from $2,3002025-06-28 MEDIUM 5.3 CVE-2025-6702 A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment… Litemall No fix yet Fix from $1,6002025-06-26 MEDIUM 5.4 CVE-2025-6707 Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administra… MongoDB 5.0.31 / 6.0.24+ Fix from $1,6002025-06-26 HIGH 8.8 CVE-2025-5822 Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote a… Maxicharger Ac Elite Business C50 Firmware 1.39.51 / 1.56.51+ Fix from $1,9502025-06-25 HIGH 8.1 CVE-2025-52890 Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates n… Patch available Fix from $1,9502025-06-25 HIGH 8.1 CVE-2025-48466 Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs… Wise 4060lan Firmware No fix yet Fix from $1,9502025-06-24 MEDIUM 5.0 CVE-2025-52918 Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces. Mitigation only Fix from $1,6002025-06-21 HIGH 7.5 CVE-2025-52487 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN… Dotnetnuke 10.0.1+ Fix from $1,9502025-06-21 HIGH 8.8 CVE-2025-5071 The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow… Ai Engine 2.8.4+ Fix from $1,9502025-06-19 CRITICAL 9.8 CVE-2025-49825EPSS 8% Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 … Mitigation only Fix from $2,3002025-06-17 HIGH 8.8 CVE-2025-49586 XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all us… Xwiki 16.4.7 / 16.10.3+ Fix from $1,9502025-06-13 MEDIUM 5.3 CVE-2025-6003 The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in… Mitigation only Fix from $1,6002025-06-12 HIGH 8.8 CVE-2025-48445 Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redire… Commerce Eurobank \(redirect\) 2.1.1+ Fix from $1,9502025-06-11 HIGH 8.8 CVE-2025-48446 Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirec… Commerce Alphabank Redirect 1.0.3+ Fix from $1,9502025-06-11 HIGH 7.8 CVE-2024-7457 The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of macOS’s authorization model. Instead of validating the… Mitigation only Fix from $1,9502025-06-11 MEDIUM 5.5 CVE-2024-8270 The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling t… Mitigation only Fix from $1,6002025-06-11 MEDIUM 6.8 CVE-2025-36578 Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access… Wyse Management Suite 5.2+ Fix from $1,6002025-06-10 MEDIUM 6.5 CVE-2025-40567 A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2), SCALANCE XCH328 (6GK5328-4TS01-2EC2) (All versions <… Mitigation only Fix from $1,6002025-06-10 MEDIUM 6.5 CVE-2025-40668 Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of … Gim Mitigation only Fix from $1,6002025-06-09 MEDIUM 6.5 CVE-2025-40669 Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each o… Gim Mitigation only Fix from $1,6002025-06-09 HIGH 8.8 CVE-2025-40670 Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many priv… Gim Mitigation only Fix from $1,9502025-06-09 CRITICAL 9.1 CVE-2025-48935 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's per… Deno 2.2.5+ Fix from $2,3002025-06-04