Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Revive Adserver MEDIUM 6.5
CVE-2025-52670

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accou…

Fix: after 6.0.1
Fix from $1,600 2025-11-20
Rallly HIGH 8.1
CVE-2025-65033

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any a…

Fix: 4.5.4+
Fix from $1,950 2025-11-19
Rallly HIGH 8.1
CVE-2025-65034

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerability allows any authenticated …

Fix: 4.5.4+
Fix from $1,950 2025-11-19
Rallly MEDIUM 6.5
CVE-2025-65028

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a…

Fix: 4.5.4+
Fix from $1,600 2025-11-19
Rallly HIGH 8.1
CVE-2025-65029

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a…

Fix: 4.5.4+
Fix from $1,950 2025-11-19
Rallly HIGH 7.1
CVE-2025-65030

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment deletion API allows any auth…

Fix: 4.5.4+
Fix from $1,950 2025-11-19
Rallly MEDIUM 6.5
CVE-2025-65031

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in the comment creation endpoint a…

Fix: 4.5.4+
Fix from $1,600 2025-11-19
Rallly MEDIUM 6.5
CVE-2025-65032

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability allows a…

Fix: 4.5.4+
Fix from $1,600 2025-11-19
Rallly MEDIUM 6.5
CVE-2025-65020

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability in the p…

Fix: 4.5.4+
Fix from $1,600 2025-11-19
Rallly CRITICAL 9.1
CVE-2025-65021

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists i…

Fix: 4.5.4+
Fix from $2,300 2025-11-19
Athoc MEDIUM 5.0
CVE-2025-12766

An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) version 7.21 could allow an attacke…

Mitigation only
Fix from $1,600 2025-11-19
Unclassified MEDIUM 5.3
CVE-2025-12427

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via…

Mitigation only
Fix from $1,600 2025-11-19
Hospital Management System MEDIUM 6.5
CVE-2025-63513

kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.

No fix yet
Fix from $1,600 2025-11-18
Unclassified MEDIUM 5.4
CVE-2025-12524

The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.0 due to missing …

Mitigation only
Fix from $1,600 2025-11-18
Alteryx Server MEDIUM 5.4
CVE-2025-63291

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by t…

Fix: after 2022.1.1.42654
Fix from $1,600 2025-11-14
Unclassified HIGH 8.1
CVE-2025-8855

Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable…

Mitigation only
Fix from $1,950 2025-11-14
Typebot HIGH 7.5
CVE-2025-64706

Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerabil…

Fix: 3.13.0+
Fix from $1,950 2025-11-13
Unclassified MEDIUM 5.3
CVE-2025-41069

Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to access or modify unauthorize…

Mitigation only
Fix from $1,600 2025-11-13
Filebrowser HIGH 8.8
CVE-2025-64523

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Ve…

Fix: 2.45.1+
Fix from $1,950 2025-11-12
Unclassified HIGH 7.5
CVE-2025-12903

The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-…

Mitigation only
Fix from $1,950 2025-11-12
Unclassified MEDIUM 5.4
CVE-2025-12126

The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via sever…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 5.3
CVE-2025-11532

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validatio…

Mitigation only
Fix from $1,600 2025-11-11
Skuul MEDIUM 5.3
CVE-2025-12918

A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file /…

Fix: after 2.6.5
Fix from $1,600 2025-11-09
Unclassified MEDIUM 5.3
CVE-2025-12353

The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to un…

Mitigation only
Fix from $1,600 2025-11-08
Unclassified HIGH 8.7
CVE-2025-64431

Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) att…

Patch available
Fix from $1,950 2025-11-07
Unclassified CRITICAL 9.8
CVE-2025-58627

Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Exploiting Incorrectly Co…

Mitigation only
Fix from $2,300 2025-11-06
Dwsurvey HIGH 7.5
CVE-2025-63248

DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another quest…

No fix yet
Fix from $1,950 2025-11-05
Unclassified HIGH 8.5
CVE-2025-11690

An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of …

Mitigation only
Fix from $1,950 2025-11-04
Unclassified CRITICAL 9.9
CVE-2025-0987

Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection. This issue affects CVLand: …

Mitigation only
Fix from $2,300 2025-11-03
Unclassified HIGH 8.8
CVE-2025-6574

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1…

Mitigation only
Fix from $1,950 2025-11-01