Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.1 CVE-2025-43561EPSS 21% ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code… Coldfusion Mitigation only Fix from $2,3002025-05-13 HIGH 7.2 CVE-2025-4646 Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.0… Centreon Web 24.04.10 / 24.10.4+ Fix from $1,9502025-05-13 HIGH 8.8 CVE-2025-27696 Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read… Superset 4.1.2+ Fix from $1,9502025-05-13 MEDIUM 5.5 CVE-2025-30440 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be abl… macOS 13.7.6 / 14.7.6+ Fix from $1,6002025-05-12 HIGH 8.8 CVE-2025-29827 Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. Azure Automation Mitigation only Fix from $1,9502025-05-08 HIGH 7.5 CVE-2025-26842 An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to use… Znuny after 7.1.3 Fix from $1,9502025-05-08 HIGH 8.8 CVE-2025-46265 On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher priv… F5os A after 1.6.2 Fix from $1,9502025-05-07 HIGH 8.1 CVE-2025-36546 On an F5OS system, if the root user had previously configured the system to allow login via SSH key-based authentication, and then enabled Appliance … F5os A 1.5.3+ Fix from $1,9502025-05-07 MEDIUM 6.7 CVE-2025-3272 Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager.  The vulnerability could allow authenticated users to change their pas… Mitigation only Fix from $1,6002025-05-07 CRITICAL 9.4 CVE-2025-3476 Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated us… Mitigation only Fix from $2,3002025-05-07 MEDIUM 5.3 CVE-2025-3609 The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to t… Mitigation only Fix from $1,6002025-05-06 HIGH 8.8 CVE-2025-3879 Vault Community, Vault Enterprise (“Vault”) Azure Auth method did not correctly validate the claims in the Azure-issued token, resulting in the poten… Vault 1.16.18 / 1.17.14+ Fix from $1,9502025-05-02 HIGH 7.4 CVE-2025-46569 Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API … Patch available Fix from $1,9502025-05-01 HIGH 7.8 CVE-2025-23244 NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an unprivileged attacker to escalate permissions. A successful exploit… Mitigation only Fix from $1,9502025-05-01 HIGH 7.5 CVE-2025-40619 Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without… Bookgy Mitigation only Fix from $1,9502025-04-29 CRITICAL 9.8 CVE-2025-3963 A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processin… Books Management System No fix yet Fix from $2,3002025-04-27 CRITICAL 9.8 CVE-2025-3960 A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionali… Books Management System No fix yet Fix from $2,3002025-04-27 MEDIUM 5.4 CVE-2025-3861 The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misc… Mitigation only Fix from $1,6002025-04-25 MEDIUM 6.5 CVE-2025-46544 In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles. Sherpa Orchestrator Mitigation only Fix from $1,6002025-04-25 MEDIUM 5.4 CVE-2024-10306 A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the for… Patch available Fix from $1,6002025-04-23 HIGH 8.1 CVE-2025-43922 The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM. Mitigation only Fix from $1,9502025-04-21 MEDIUM 5.5 CVE-2024-12862 Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the appropriate permissions to r… Mitigation only Fix from $1,6002025-04-21 MEDIUM 6.1 CVE-2025-3838 An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the cust… Mitigation only Fix from $1,6002025-04-21 MEDIUM 5.3 CVE-2025-43921 GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple… Mailman after 2.1.39 Fix from $1,6002025-04-20 HIGH 8.2 CVE-2025-43917 In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifica… Mitigation only Fix from $1,9502025-04-19 MEDIUM 6.5 CVE-2025-32796 Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enabl… Dify after 0.6.8 Fix from $1,6002025-04-18 MEDIUM 6.5 CVE-2024-49808 IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to impro… Sterling Connect Direct Web Services 6.1.0.28 / 6.2.0.27+ Fix from $1,6002025-04-18 MEDIUM 5.3 CVE-2025-3453 The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and mor… Mitigation only Fix from $1,6002025-04-17 MEDIUM 6.1 CVE-2025-21582 Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affect… Crm Technical Foundation after 12.2.14 Fix from $1,6002025-04-15 MEDIUM 5.4 CVE-2025-32068 Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawi… Mitigation only Fix from $1,6002025-04-11