Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 8.8
CVE-2025-5949

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0…

Mitigation only
Fix from $1,950 2025-11-01
Unclassified MEDIUM 5.0
CVE-2025-61876

Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an authenticated user with low priv…

Mitigation only
Fix from $1,600 2025-10-29
Unclassified MEDIUM 6.5
CVE-2025-64283

Authorization Bypass Through User-Controlled Key vulnerability in Rometheme RTMKit rometheme-for-elementor allows Exploiting Incorrectly Configured A…

Mitigation only
Fix from $1,600 2025-10-29
Pharmacare HIGH 8.8
CVE-2025-12288

A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the comp…

Fix: after 9.4
Fix from $1,950 2025-10-27
Unclassified MEDIUM 6.8
CVE-2025-12351

Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this v…

Mitigation only
Fix from $1,600 2025-10-27
Client Details System HIGH 8.1
CVE-2025-12283

A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown function. The manipulation results…

No fix yet
Fix from $1,950 2025-10-27
Learnhouse HIGH 7.5
CVE-2025-12270

A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an unknown function of the file …

Fix: after 2025-09-21
Fix from $1,950 2025-10-27
Unclassified HIGH 8.6
CVE-2025-34293

GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to t…

Mitigation only
Fix from $1,950 2025-10-24
Devolutions Server HIGH 8.4
CVE-2025-11957

Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-appr…

Fix: 2025.2.14.0+
Fix from $1,950 2025-10-22
Unclassified MEDIUM 6.5
CVE-2025-49952

Authorization Bypass Through User-Controlled Key vulnerability in favethemes Houzez houzez allows Exploiting Incorrectly Configured Access Control Se…

Mitigation only
Fix from $1,600 2025-10-22
Unclassified MEDIUM 5.5
CVE-2025-8884

Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of…

Mitigation only
Fix from $1,600 2025-10-20
Unclassified MEDIUM 5.3
CVE-2025-11741

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via t…

Mitigation only
Fix from $1,600 2025-10-18
Unclassified HIGH 7.5
CVE-2025-11517

The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to …

Mitigation only
Fix from $1,950 2025-10-18
Pega Platform MEDIUM 6.5
CVE-2025-9559

Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only …

Fix: 23.1.5+
Fix from $1,600 2025-10-16
Strapi HIGH 8.2
CVE-2024-56143

Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document ser…

Fix: 5.5.2+
Fix from $1,950 2025-10-16
Exito HIGH 7.5
CVE-2025-41020

Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to ot…

Mitigation only
Fix from $1,950 2025-10-16
Unclassified CRITICAL 9.8
CVE-2025-10742

The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.8.6. This is due to the …

Mitigation only
Fix from $2,300 2025-10-16
Sipass Integrated MEDIUM 5.3
CVE-2025-40773

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnera…

Fix: 3.00+
Fix from $1,600 2025-10-14
Unclassified HIGH 7.5
CVE-2025-9902

Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trade Co. Ltd. QRMenu allows Priv…

Mitigation only
Fix from $1,950 2025-10-13
Unica Centralized Offer Management HIGH 7.5
CVE-2025-31997

HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access re…

Fix: 25.1.0.1+
Fix from $1,950 2025-10-12
Unclassified MEDIUM 5.3
CVE-2025-11518

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5…

Mitigation only
Fix from $1,600 2025-10-11
Unclassified MEDIUM 6.1
CVE-2025-8887

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in …

Mitigation only
Fix from $1,600 2025-10-10
Unclassified HIGH 8.7
CVE-2025-61779

Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions …

Patch available
Fix from $1,950 2025-10-09
Unclassified HIGH 8.8
CVE-2025-6038

The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via p…

Mitigation only
Fix from $1,950 2025-10-09
Unclassified MEDIUM 5.3
CVE-2025-40676

Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Research Infrastructure (BBMRI-ER…

Mitigation only
Fix from $1,600 2025-10-07
Unclassified MEDIUM 6.0
CVE-2025-0606

Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing, Resource Leak Exposure. Th…

Mitigation only
Fix from $1,600 2025-10-06
Unclassified MEDIUM 6.3
CVE-2025-0642

Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Software and Consulting Ltd. Co. As…

No fix yet
Fix from $1,600 2025-10-02
Collegetivity HIGH 8.1
CVE-2025-56392

An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other user…

No fix yet
Fix from $1,950 2025-09-30
Bold Workplanner HIGH 7.5
CVE-2025-41098

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a  misuse of the g…

Fix: 2.5.25+
Fix from $1,950 2025-09-30
Bold Workplanner MEDIUM 6.5
CVE-2025-41099

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate…

Fix: 2.5.25+
Fix from $1,600 2025-09-30