Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified CRITICAL 9.8
CVE-2025-15001

The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.…

Mitigation only
Fix from $2,300 2026-01-06
Unclassified CRITICAL 9.8
CVE-2025-14996

The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up…

Mitigation only
Fix from $2,300 2026-01-06
Unclassified HIGH 8.6
CVE-2025-68044

Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploit…

Mitigation only
Fix from $1,950 2026-01-05
Bagisto HIGH 7.1
CVE-2026-21447

Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer orde…

Fix: 2.3.10+
Fix from $1,950 2026-01-02
Unclassified CRITICAL 9.8
CVE-2025-14998

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due …

Mitigation only
Fix from $2,300 2026-01-02
Unclassified MEDIUM 5.3
CVE-2025-49334

Authorization Bypass Through User-Controlled Key vulnerability in Eduardo Villão MyD Delivery myd-delivery allows Exploiting Incorrectly Configured A…

No fix yet
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.3
CVE-2025-63053

Authorization Bypass Through User-Controlled Key vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Exploiting Incorrectl…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-69029

Authorization Bypass Through User-Controlled Key vulnerability in Select-Themes Struktur struktur allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,600 2025-12-30
Backpack Traveler MEDIUM 5.4
CVE-2025-69030

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Conf…

Fix: after 2.10.3
Fix from $1,600 2025-12-30
Fivestar MEDIUM 5.4
CVE-2025-69032

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Incorrectly Configured Access Con…

Fix: after 1.7
Fix from $1,600 2025-12-30
Unclassified MEDIUM 5.3
CVE-2025-68997

Authorization Bypass Through User-Controlled Key vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Co…

Mitigation only
Fix from $1,600 2025-12-30
Unclassified MEDIUM 5.3
CVE-2025-68979

Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Inco…

Mitigation only
Fix from $1,600 2025-12-30
Axios Cache Interceptor MEDIUM 6.5
CVE-2025-69202

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth token…

Fix: 1.11.1+
Fix from $1,600 2025-12-29
Unclassified CRITICAL 9.8
CVE-2019-25235

Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages b…

Mitigation only
Fix from $2,300 2025-12-24
Unclassified HIGH 7.5
CVE-2018-25129

SOCA Access Control System 180612 contains multiple insecure direct object reference vulnerabilities that allow attackers to access sensitive user cr…

No fix yet
Fix from $1,950 2025-12-24
Unclassified HIGH 7.5
CVE-2025-67909

Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting I…

Mitigation only
Fix from $1,950 2025-12-24
Orangescrum HIGH 8.8
CVE-2021-47721

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manip…

No fix yet
Fix from $1,950 2025-12-23
Stream Extension CRITICAL 9.8
CVE-2023-53955

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and acces…

Mitigation only
Fix from $2,300 2025-12-22
Turms MEDIUM 6.5
CVE-2025-66911

Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handle…

No fix yet
Fix from $1,600 2025-12-19
Unclassified MEDIUM 5.3
CVE-2025-63043

Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly …

Mitigation only
Fix from $1,600 2025-12-18
Soliclub HIGH 7.5
CVE-2025-1031

Authorization Bypass Through User-Controlled Key vulnerability in Utarit Informatics Services Inc. SoliClub allows Functionality Misuse. This issue …

Fix: 5.3.7+
Fix from $1,950 2025-12-18
Unclassified CRITICAL 9.3
CVE-2025-10910

A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker…

Mitigation only
Fix from $2,300 2025-12-18
Unclassified MEDIUM 6.5
CVE-2025-10019

Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly C…

Mitigation only
Fix from $1,600 2025-12-18
Projectsend HIGH 7.5
CVE-2023-53930

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manip…

No fix yet
Fix from $1,950 2025-12-17
Ulicms CRITICAL 9.8
CVE-2023-53914

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in …

Mitigation only
Fix from $2,300 2025-12-17
Avideo HIGH 8.8
CVE-2025-34436

AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object…

Fix: 20.0+
Fix from $1,950 2025-12-17
Avideo HIGH 8.8
CVE-2025-34437

AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentic…

Fix: 20.0+
Fix from $1,950 2025-12-17
Avideo HIGH 8.1
CVE-2025-34438

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation…

Fix: 20.0+
Fix from $1,950 2025-12-17
Avideo MEDIUM 6.5
CVE-2025-34435

AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files b…

Fix: 20.0+
Fix from $1,600 2025-12-17
Pagekit CRITICAL 9.8
CVE-2025-67165

An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.

Mitigation only
Fix from $2,300 2025-12-17