Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Serv U HIGH 7.2
CVE-2025-40541

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute nativ…

Fix: 15.5.4+
Fix from $1,950 2026-02-24
Security Center MEDIUM 6.5
CVE-2026-2698

An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

Fix: 6.8.0+
Fix from $1,600 2026-02-23
Security Center HIGH 8.8
CVE-2026-2697

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

Fix: 6.8.0+
Fix from $1,950 2026-02-23
Unclassified MEDIUM 5.4
CVE-2026-2997

Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers…

Mitigation only
Fix from $1,600 2026-02-23
Smanga CRITICAL 9.4
CVE-2025-70833

An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administra…

Mitigation only
Fix from $2,300 2026-02-20
E Commerce HIGH 8.1
CVE-2025-15582

A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update of the component Product Mana…

No fix yet
Fix from $1,950 2026-02-20
Unclassified HIGH 7.5
CVE-2026-24950

Authorization Bypass Through User-Controlled Key vulnerability in themeplugs Authorsy authorsy allows Exploiting Incorrectly Configured Access Contro…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 7.5
CVE-2026-22383

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allow…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 7.5
CVE-2025-69394

Authorization Bypass Through User-Controlled Key vulnerability in cnvrse Cnvrse cnvrse allows Exploiting Incorrectly Configured Access Control Securi…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified MEDIUM 6.5
CVE-2025-68514

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting In…

Mitigation only
Fix from $1,600 2026-02-20
Unclassified HIGH 7.5
CVE-2025-68051

Authorization Bypass Through User-Controlled Key vulnerability in Shiprocket Shiprocket shiprocket allows Exploiting Incorrectly Configured Access Co…

Mitigation only
Fix from $1,950 2026-02-20
Panel HIGH 8.1
CVE-2026-26016

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization…

Fix: 1.12.1+
Fix from $1,950 2026-02-19
Unclassified HIGH 7.3
CVE-2025-9062

Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified MEDIUM 5.3
CVE-2026-1219

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versi…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 5.3
CVE-2026-25324

Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incor…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 5.3
CVE-2026-25005

Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrect…

Mitigation only
Fix from $1,600 2026-02-19
Unclassified MEDIUM 5.3
CVE-2025-13842

The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions up to and including 7.5.0. Th…

Mitigation only
Fix from $1,600 2026-02-19
Hospital Management System MEDIUM 6.5
CVE-2025-70063

The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The app…

No fix yet
Fix from $1,600 2026-02-18
Graylog MEDIUM 6.5
CVE-2026-1436

Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can acces…

Mitigation only
Fix from $1,600 2026-02-18
Unclassified MEDIUM 5.4
CVE-2026-1987

The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due …

Mitigation only
Fix from $1,600 2026-02-14
Flexcity HIGH 8.3
CVE-2026-1619

Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers. …

Fix: 1.0.36+
Fix from $1,950 2026-02-13
E Commerce Package MEDIUM 6.3
CVE-2025-13004

Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Manipulating Us…

Fix: after 2025-11-27
Fix from $1,600 2026-02-12
Unclassified HIGH 8.8
CVE-2025-15096

The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and includin…

Mitigation only
Fix from $1,950 2026-02-11
Unclassified MEDIUM 5.4
CVE-2025-10912

Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Manipulating User…

Mitigation only
Fix from $1,600 2026-02-11
Unclassified HIGH 8.8
CVE-2025-7347

Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Tracking System allows Exploitation …

Mitigation only
Fix from $1,950 2026-02-10
Camera Station Pro MEDIUM 5.7
CVE-2025-12063

An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.

Fix: 6.14.10768+
Fix from $1,600 2026-02-10
Craft Cms HIGH 8.8
CVE-2026-25497

Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege…

Fix: 4.17.0 / 5.9.0+
Fix from $1,950 2026-02-09
Markus MEDIUM 6.5
CVE-2026-24900

MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_id>/assignments/<:assignment_…

Fix: 2.9.1+
Fix from $1,600 2026-02-09
Wekan HIGH 7.5
CVE-2026-25563

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementatio…

Fix: 8.19+
Fix from $1,950 2026-02-07
Wekan HIGH 7.5
CVE-2026-25564

WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementatio…

Fix: 8.19+
Fix from $1,950 2026-02-07