Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified MEDIUM 5.4
CVE-2026-22398

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fleur fleur allows Exploiting Incorrectly Configured Access Control S…

No fix yet
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-22400

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Holmes holmes allows Exploiting Incorrectly Configured Access Control…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-22391

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Cocco cocco allows Exploiting Incorrectly Configured Access Control S…

No fix yet
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-22393

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectly Configured Access Control S…

No fix yet
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-22396

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fiorello fiorello allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,600 2026-01-22
Typebot HIGH 7.4
CVE-2025-65098

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credential…

Fix: 3.13.2+
Fix from $1,950 2026-01-22
Unclassified HIGH 7.5
CVE-2025-10855

Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows Exploitation of Trusted Identi…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 7.5
CVE-2025-10024

Authorization Bypass Through User-Controlled Key vulnerability in EXERT Computer Technologies Software Ltd. Co. Education Management System allows Pa…

Mitigation only
Fix from $1,950 2026-01-22
Mastodon MEDIUM 5.4
CVE-2026-23964

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object re…

Fix: 4.3.18 / 4.4.12+
Fix from $1,600 2026-01-22
D View 8 HIGH 8.8
CVE-2026-23754

D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can su…

Fix: after 2.0.1.107
Fix from $1,950 2026-01-21
Unclassified CRITICAL 9.8
CVE-2025-15521

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeove…

Mitigation only
Fix from $2,300 2026-01-21
Unclassified HIGH 7.1
CVE-2026-23843

teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients. Prior to commit dd082a134a2…

Patch available
Fix from $1,950 2026-01-19
Restrict Content HIGH 7.5
CVE-2025-14844

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 vi…

Fix: 3.2.17+
Fix from $1,950 2026-01-16
Glpi HIGH 7.5
CVE-2025-64516

GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any …

Fix: 10.0.21 / 11.0.3+
Fix from $1,950 2026-01-15
Cal.com CRITICAL 9.8
CVE-2026-23478

Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attack…

Fix: 6.0.7+
Fix from $2,300 2026-01-13
Unclassified CRITICAL 10.0
CVE-2025-40805

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to c…

Mitigation only
Fix from $2,300 2026-01-13
Xmall HIGH 8.2
CVE-2023-36331

Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulatio…

No fix yet
Fix from $1,950 2026-01-12
Inbox HIGH 8.1
CVE-2025-41077

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all user…

Fix: 4.5.27+
Fix from $1,950 2026-01-12
Dx Netops Spectrum HIGH 8.8
CVE-2025-69274

Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issu…

Fix: 24.3.11+
Fix from $1,950 2026-01-12
Spree HIGH 7.5
CVE-2026-22589

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure …

Fix: 4.10.2 / 5.0.7+
Fix from $1,950 2026-01-10
Unclassified HIGH 7.5
CVE-2025-13457

The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get…

Mitigation only
Fix from $1,950 2026-01-10
Unclassified MEDIUM 5.9
CVE-2026-21409

Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication bet…

Mitigation only
Fix from $1,600 2026-01-09
Spree MEDIUM 6.5
CVE-2026-22588

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Di…

Fix: 4.10.2 / 5.0.7+
Fix from $1,600 2026-01-08
Ecase Portal CRITICAL 9.8
CVE-2026-22234

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predict…

Fix: 9.0.45.0+
Fix from $2,300 2026-01-08
Ecase Ecomplaint HIGH 7.5
CVE-2026-22235

OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'ch…

Fix: 9.0.45.0+
Fix from $1,950 2026-01-08
Unclassified MEDIUM 5.3
CVE-2025-4596

Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging to other users through manipul…

Mitigation only
Fix from $1,600 2026-01-08
Unclassified MEDIUM 6.5
CVE-2025-67919

Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access…

Mitigation only
Fix from $1,600 2026-01-08
Unclassified CRITICAL 9.8
CVE-2025-15018

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This…

Mitigation only
Fix from $2,300 2026-01-07
Unclassified MEDIUM 5.4
CVE-2025-14802

The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and including, 4.3.2.2 via the /wp…

Mitigation only
Fix from $1,600 2026-01-07
Bravia Signage CRITICAL 9.8
CVE-2020-36923

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. …

Fix: after 1.7.8
Fix from $2,300 2026-01-06