Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.1
CVE-2025-14101

Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploitation of Trusted Identifiers…

Mitigation only
Fix from $1,950 2025-12-17
Ninja Forms HIGH 7.5
CVE-2025-11924

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up …

Fix: 3.13.1+
Fix from $1,950 2025-12-17
Unclassified HIGH 7.5
CVE-2025-13474

Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation of Trusted Identifiers. This …

Mitigation only
Fix from $1,950 2025-12-16
Unclassified MEDIUM 6.5
CVE-2025-68071

Authorization Bypass Through User-Controlled Key vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly C…

Mitigation only
Fix from $1,600 2025-12-16
Unclassified MEDIUM 5.3
CVE-2025-67985

Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows Exploiting Incorre…

Mitigation only
Fix from $1,600 2025-12-16
Unclassified MEDIUM 5.3
CVE-2025-66132

Authorization Bypass Through User-Controlled Key vulnerability in FAPI Business s.r.o. FAPI Member fapi-member allows Exploiting Incorrectly Configur…

No fix yet
Fix from $1,600 2025-12-16
Fineract HIGH 8.1
CVE-2025-58137

Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is …

Fix: 1.12.1+
Fix from $1,950 2025-12-12
Unclassified MEDIUM 5.3
CVE-2025-12883

The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2…

Mitigation only
Fix from $1,600 2025-12-12
Unclassified HIGH 7.6
CVE-2025-13124

Authorization Bypass Through User-Controlled Key vulnerability in Netiket Information Technologies Ltd. Co. ApplyLogic allows Exploitation of Trusted…

No fix yet
Fix from $1,950 2025-12-11
Unclassified HIGH 7.6
CVE-2025-13003

Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard allows Exploitation of Truste…

Mitigation only
Fix from $1,950 2025-12-11
I Media Server Digital Signage HIGH 7.5
CVE-2020-36895

EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access …

No fix yet
Fix from $1,950 2025-12-10
Unclassified HIGH 8.3
CVE-2025-41358

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authe…

Mitigation only
Fix from $1,950 2025-12-10
Unclassified MEDIUM 5.3
CVE-2025-63065

Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Exploiting Inc…

Mitigation only
Fix from $1,600 2025-12-09
Mitarbeiter Portal HIGH 8.1
CVE-2025-61075

Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users …

Fix: 2.16.1+
Fix from $1,950 2025-12-09
Tuleap MEDIUM 6.5
CVE-2025-64497

Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Editi…

Fix: 16.12-10 / 16.13-7+
Fix from $1,600 2025-12-08
Unclassified MEDIUM 5.3
CVE-2025-13748

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje…

Mitigation only
Fix from $1,600 2025-12-06
Tables MEDIUM 5.3
CVE-2025-66513

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric…

Fix: 0.8.9 / 0.9.6+
Fix from $1,600 2025-12-05
Unclassified HIGH 8.3
CVE-2025-13932

The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticat…

Mitigation only
Fix from $1,950 2025-12-04
Edupluscampus MEDIUM 6.5
CVE-2025-61148

An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other st…

No fix yet
Fix from $1,600 2025-12-04
Romm MEDIUM 6.5
CVE-2025-65097

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4…

Fix: 4.4.1+
Fix from $1,600 2025-12-03
Gams MEDIUM 6.5
CVE-2025-41086

Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage res…

Fix: 48.7.0 / 49.7.0+
Fix from $1,600 2025-12-02
Grav MEDIUM 6.5
CVE-2025-66306

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Pa…

Fix: 1.8.0+
Fix from $1,600 2025-12-01
Unclassified CRITICAL 9.8
CVE-2025-13615

The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the p…

Mitigation only
Fix from $2,300 2025-11-30
Webitr HIGH 8.8
CVE-2025-13768

WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by …

Fix: 2_1_0_34+
Fix from $1,950 2025-11-28
Unclassified MEDIUM 5.3
CVE-2025-13157

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 …

Mitigation only
Fix from $1,600 2025-11-27
Classroomio HIGH 7.5
CVE-2025-65672

Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings.

No fix yet
Fix from $1,950 2025-11-26
Project Contract Management MEDIUM 5.3
CVE-2025-64067

Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to im…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified MEDIUM 5.3
CVE-2025-13389

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a mi…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified MEDIUM 6.5
CVE-2025-12040

The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.3 via s…

Mitigation only
Fix from $1,600 2025-11-25
Unclassified MEDIUM 5.4
CVE-2025-12881

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl…

Mitigation only
Fix from $1,600 2025-11-21