Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.0 CVE-2025-26330 Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local a… Powerscale Onefs after 9.10.1.1 Fix from $1,9502025-04-10 MEDIUM 6.5 CVE-2025-3475 Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoo… Web T 1.1.0+ Fix from $1,6002025-04-09 HIGH 7.5 CVE-2025-31481 API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured secu… Patch available Fix from $1,9502025-04-03 CRITICAL 9.1 CVE-2024-38392 Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the ap… Mitigation only Fix from $2,3002025-04-02 CRITICAL 9.8 CVE-2025-24233 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5.… macOS 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 HIGH 7.5 CVE-2025-24221 This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, visionOS 2.4. Sensiti… Ipados 2.4 / 17.7.6+ Fix from $1,9502025-03-31 MEDIUM 5.3 CVE-2025-30209 Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or info… Tuleap 16.4-10 / 16.5-6+ Fix from $1,6002025-03-31 HIGH 8.1 CVE-2025-30093 HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass auth… Htcondor 23.0.22 / 23.10.22+ Fix from $1,9502025-03-27 HIGH 8.8 CVE-2025-2242 An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 1… GitLab 17.8.6 / 17.9.3+ Fix from $1,9502025-03-27 MEDIUM 6.5 CVE-2024-55965 An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (spe… Appsmith 1.51+ Fix from $1,6002025-03-26 CRITICAL 9.1 CVE-2025-29927EPSS 99% Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and … Next.js 12.3.5 / 13.5.9+ Fix from $2,3002025-03-21 MEDIUM 6.5 CVE-2025-30179 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attac… Mattermost Server 9.11.9 / 10.3.4+ Fix from $1,6002025-03-21 HIGH 8.8 CVE-2025-25274 Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authen… Mattermost Server 9.11.9 / 10.3.4+ Fix from $1,9502025-03-21 HIGH 7.8 CVE-2024-44305 This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able to gain root privileges. macOS 14.6+ Fix from $1,9502025-03-21 CRITICAL 9.8 CVE-2025-26853 DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema. Infocad 3.5.2.0+ Fix from $2,3002025-03-20 MEDIUM 6.5 CVE-2024-9159 An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the s… Chuanhuchatgpt No fix yet Fix from $1,6002025-03-20 MEDIUM 6.1 CVE-2024-9098 In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, … Lunary 1.4.30+ Fix from $1,6002025-03-20 MEDIUM 6.7 CVE-2024-7039 In open-webui/open-webui version v0.3.8, there is an improper privilege management vulnerability. The application allows an attacker, acting as an ad… Open Webui No fix yet Fix from $1,6002025-03-20 HIGH 7.3 CVE-2024-10275 In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change… Lunary 1.5.7+ Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-10273 In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The … Lunary 1.5.7+ Fix from $1,6002025-03-20 HIGH 8.3 CVE-2024-10109 A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "… Anythingllm 1.3.1+ Fix from $1,9502025-03-20 HIGH 7.5 CVE-2025-29924 XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private informatio… Xwiki 15.10.14 / 16.4.6+ Fix from $1,9502025-03-19 MEDIUM 6.9 CVE-2025-2202 Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to … Mitigation only Fix from $1,6002025-03-17 MEDIUM 6.9 CVE-2025-2201 Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive in… Mitigation only Fix from $1,6002025-03-17 HIGH 7.8 CVE-2025-30074 Alludo Parallels Desktop before 19.4.2 and 20.x before 20.2.2 for macOS on Intel platforms allows privilege escalation to root via the VM creation ro… Mitigation only Fix from $1,9502025-03-16 CRITICAL 9.8 CVE-2025-27138 DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the i… Dataease 2.10.6+ Fix from $2,3002025-03-13 HIGH 8.2 CVE-2025-29997 This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated remote a… Mitigation only Fix from $1,9502025-03-13 MEDIUM 6.5 CVE-2025-0652 An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, … GitLab 17.7.7 / 17.8.5+ Fix from $1,6002025-03-13 MEDIUM 6.4 CVE-2025-27602 Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1… Umbraco Cms 10.8.9 / 13.7.1+ Fix from $1,6002025-03-11 HIGH 7.8 CVE-2024-45328 An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated … Fortisandbox 4.4.7+ Fix from $1,9502025-03-11