Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Spree MEDIUM 5.3
CVE-2026-25757

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can vi…

Fix: 5.0.8 / 5.1.10+
Fix from $1,600 2026-02-06
Spree HIGH 7.5
CVE-2026-25758

Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow th…

Fix: 4.10.3 / 5.0.8+
Fix from $1,950 2026-02-06
Payload MEDIUM 5.4
CVE-2026-25574

Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vul…

Fix: 3.74.0+
Fix from $1,600 2026-02-06
Unclassified MEDIUM 5.3
CVE-2026-1271

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,…

Mitigation only
Fix from $1,600 2026-02-05
Open Eclass Platform HIGH 7.5
CVE-2026-24773

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an Insecure Direct Object Ref…

Fix: 4.2+
Fix from $1,950 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-24991

Authorization Bypass Through User-Controlled Key vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allows Exploiting Incorrectly Conf…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified MEDIUM 6.9
CVE-2026-1664

Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function within the Cloudflare Agents SDK.…

Mitigation only
Fix from $1,600 2026-02-03
Unclassified HIGH 8.1
CVE-2026-1375

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions u…

Mitigation only
Fix from $1,950 2026-02-03
Unclassified MEDIUM 5.3
CVE-2026-0909

The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.8.3.1. This is due to the…

Mitigation only
Fix from $1,600 2026-02-03
Khoj HIGH 7.1
CVE-2025-69207

Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any us…

Fix: 2.0.0+
Fix from $1,950 2026-02-02
Unclassified MEDIUM 5.4
CVE-2026-1251

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u…

Mitigation only
Fix from $1,600 2026-01-31
Db2 HIGH 7.5
CVE-2025-36365

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific configuration of cataloged remot…

Fix: after 12.1.3
Fix from $1,950 2026-01-30
Unclassified HIGH 7.5
CVE-2020-37008

EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access adm…

No fix yet
Fix from $1,950 2026-01-29
Menu Panel CRITICAL 9.8
CVE-2025-7013

Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifier…

Fix: after 29012026
Fix from $2,300 2026-01-29
Oneflow MEDIUM 6.5
CVE-2025-65887

A division-by-zero vulnerability in the flow.floor_divide() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a cra…

No fix yet
Fix from $1,600 2026-01-28
Studiocms MEDIUM 6.5
CVE-2026-24134

StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authoriz…

Fix: 0.2.0+
Fix from $1,600 2026-01-28
Grafana HIGH 8.1
CVE-2026-21721

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who…

Fix: 11.6.9 / 12.0.8+
Fix from $1,950 2026-01-27
Omada Controller MEDIUM 6.8
CVE-2025-9520

An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijac…

Fix: 6.0+
Fix from $1,600 2026-01-26
Unclassified HIGH 8.5
CVE-2025-14459

A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthor…

Mitigation only
Fix from $1,950 2026-01-26
Saleor HIGH 7.5
CVE-2026-24136

Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct…

Fix: 3.20.110 / 3.21.45+
Fix from $1,950 2026-01-24
Unclassified MEDIUM 5.3
CVE-2026-24634

Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configur…

Mitigation only
Fix from $1,600 2026-01-23
Unclassified MEDIUM 5.4
CVE-2026-24631

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Rosebud rosebud allows Exploiting Incorrectly Configured Access Contr…

No fix yet
Fix from $1,600 2026-01-23
Unclassified MEDIUM 5.3
CVE-2026-24599

Authorization Bypass Through User-Controlled Key vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrec…

Mitigation only
Fix from $1,600 2026-01-23
Gitea MEDIUM 6.5
CVE-2026-20904

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings o…

Fix: 1.25.4+
Fix from $1,600 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20912

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20897

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Unclassified CRITICAL 9.4
CVE-2026-1201

An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could a…

Mitigation only
Fix from $2,300 2026-01-22
Unclassified MEDIUM 6.5
CVE-2026-24379

Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Ac…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-22426

Authorization Bypass Through User-Controlled Key vulnerability in Elated-Themes Sweet Jane sweetjane allows Exploiting Incorrectly Configured Access …

No fix yet
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-22430

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Verdure verdure allows Exploiting Incorrectly Configured Access Contr…

Mitigation only
Fix from $1,600 2026-01-22