Vulnerability index

Browse CVEs

2,843 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
HIGH 7.5 CVE-2025-27822 An issue was discovered in the Masquerade module before 1.x-1.0.1 for Backdrop CMS. It allows people to temporarily switch to another user account. T… Mitigation only Fix from $1,9502025-03-07 HIGH 7.1 CVE-2025-2003 Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission. Devolutions Server 2024.3.13.0+ Fix from $1,9502025-03-05 CRITICAL 9.8 CVE-2025-27645 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extension Installation by Trusting … Vasion Print 20.0.2368 / 22.0.933+ Fix from $2,3002025-03-05 MEDIUM 5.5 CVE-2025-0359 During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Application framework that allowed… Axis Os 11.11.135 / 12.2.52+ Fix from $1,6002025-03-04 HIGH 7.8 CVE-2025-0360 During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th… Axis Os 11.11.135 / 12.2.41+ Fix from $1,9502025-03-04 MEDIUM 5.6 CVE-2024-2321 An incorrect authorization vulnerability exists in multiple WSO2 products, allowing protected APIs to be accessed directly using a refresh token inst… Api Manager Mitigation only Fix from $1,6002025-02-27 MEDIUM 6.5 CVE-2025-26526 Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities. Moodle 4.1.16 / 4.3.10+ Fix from $1,6002025-02-24 MEDIUM 5.3 CVE-2025-26531 Insufficient capability checks made it possible to disable badges a user does not have permission to access. Moodle 4.1.16 / 4.3.10+ Fix from $1,6002025-02-24 HIGH 8.8 CVE-2024-5705 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the c… Mitigation only Fix from $1,9502025-02-19 MEDIUM 6.5 CVE-2024-45081 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to i… Cognos Controller 11.0.1.4+ Fix from $1,6002025-02-19 MEDIUM 6.8 CVE-2024-39328 Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their configuration privileges in a… Mitigation only Fix from $1,6002025-02-18 HIGH 8.8 CVE-2025-26511 Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-1.0.0 and 4.1.2-1.0.0 through… Patch available Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-0937 Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other na… Nomad 1.7.18 / 1.8.10+ Fix from $1,9502025-02-12 HIGH 8.8 CVE-2025-1214 A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of th… Maxair No fix yet Fix from $1,9502025-02-12 MEDIUM 6.8 CVE-2024-54916 An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate priv… Mitigation only Fix from $1,6002025-02-11 CRITICAL 9.1 CVE-2025-24434EPSS 17% Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability th… Commerce Mitigation only Fix from $2,3002025-02-11 MEDIUM 5.4 CVE-2025-24437 Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability th… Commerce Mitigation only Fix from $1,6002025-02-11 HIGH 7.1 CVE-2025-24407 Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability th… Commerce B2b 1.3.3+ Fix from $1,9502025-02-11 HIGH 8.2 CVE-2025-24409 Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability t… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502025-02-11 MEDIUM 6.1 CVE-2025-24200 KEV An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7… Ipados 15.8.4 / 16.7.11+ Fix from $1,6002025-02-10 MEDIUM 5.3 CVE-2021-41528 An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentia… Mitigation only Fix from $1,6002025-02-07 MEDIUM 5.4 CVE-2025-24860 Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when usi… Cassandra 4.0.16 / 4.1.8+ Fix from $1,6002025-02-04 HIGH 8.8 CVE-2024-57434 macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super adminis… Mall Tiny No fix yet Fix from $1,9502025-01-31 HIGH 7.3 CVE-2024-23929 This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although a… Dmh Wt7600nex Firmware Mitigation only Fix from $1,9502025-01-31 HIGH 8.7 CVE-2025-24500 The vulnerability allows an unauthenticated attacker to access information in PAM database. No fix yet Fix from $1,9502025-01-30 MEDIUM 5.1 CVE-2025-24099 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker … macOS 13.7.3 / 14.7.3+ Fix from $1,6002025-01-30 MEDIUM 5.4 CVE-2024-57438 Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles. Ruoyi No fix yet Fix from $1,6002025-01-29 MEDIUM 6.5 CVE-2024-41140 Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function. Manageengine Applications Manager 17.0 / 17.3+ Fix from $1,6002025-01-29 HIGH 8.6 CVE-2025-24479 A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and all… Mitigation only Fix from $1,9502025-01-28 MEDIUM 6.5 CVE-2025-23054 A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator use… Fabric Composer 7.1.1+ Fix from $1,6002025-01-28