Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-27822
An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily switch to another user account. T…
Mitigation only
HIGH 7.1
CVE-2025-2003
Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.
Devolutions Server
2024.3.13.0+
CRITICAL 9.8
CVE-2025-27645
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extension Installation by Trusting …
Vasion Print
20.0.2368 / 22.0.933+
MEDIUM 5.5
CVE-2025-0359
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed…
Axis Os
11.11.135 / 12.2.52+
HIGH 7.8
CVE-2025-0360
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th…
Axis Os
11.11.135 / 12.2.41+
MEDIUM 5.6
CVE-2024-2321
An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token inst…
Api Manager
Mitigation only
MEDIUM 6.5
CVE-2025-26526
Separate Groups mode restrictions were not factored into permission
checks before allowing viewing or deletion of responses in Feedback
activities.
Moodle
4.1.16 / 4.3.10+
MEDIUM 5.3
CVE-2025-26531
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
Moodle
4.1.16 / 4.3.10+
HIGH 8.8
CVE-2024-5705
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the c…
Mitigation only
MEDIUM 6.5
CVE-2024-45081
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
could allow an authenticated user to modify restricted content due to i…
Cognos Controller
11.0.1.4+
MEDIUM 6.8
CVE-2024-39328
Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a…
Mitigation only
HIGH 8.8
CVE-2025-26511
Systems running the Instaclustr
fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0
through 4.0.16-1.0.0 and 4.1.2-1.0.0 through…
Patch available
HIGH 7.1
CVE-2025-0937
Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other na…
Nomad
1.7.18 / 1.8.10+
HIGH 8.8
CVE-2025-1214
A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of th…
Maxair
No fix yet
MEDIUM 6.8
CVE-2024-54916
An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate priv…
Mitigation only
CRITICAL 9.1
CVE-2025-24434EPSS 17%
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability th…
Commerce
Mitigation only
MEDIUM 5.4
CVE-2025-24437
Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability th…
Commerce
Mitigation only
HIGH 7.1
CVE-2025-24407
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability th…
Commerce B2b
1.3.3+
HIGH 8.2
CVE-2025-24409
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability t…
Commerce
1.3.3 / 2.4.4+
MEDIUM 6.1
CVE-2025-24200 KEV
An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7…
Ipados
15.8.4 / 16.7.11+
MEDIUM 5.3
CVE-2021-41528
An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentia…
Mitigation only
MEDIUM 5.4
CVE-2025-24860
Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when usi…
Cassandra
4.0.16 / 4.1.8+
HIGH 8.8
CVE-2024-57434
macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super adminis…
Mall Tiny
No fix yet
HIGH 7.3
CVE-2024-23929
This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although a…
Dmh Wt7600nex Firmware
Mitigation only
HIGH 8.7
CVE-2025-24500
The vulnerability allows an unauthenticated attacker to access information in PAM database.
No fix yet
MEDIUM 5.1
CVE-2025-24099
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker …
macOS
13.7.3 / 14.7.3+
MEDIUM 5.4
CVE-2024-57438
Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.
Ruoyi
No fix yet
MEDIUM 6.5
CVE-2024-41140
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
Manageengine Applications Manager
17.0 / 17.3+
HIGH 8.6
CVE-2025-24479
A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and all…
Mitigation only
MEDIUM 6.5
CVE-2025-23054
A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator use…
Fabric Composer
7.1.1+