Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified MEDIUM 5.3
CVE-2025-10947

A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of the file /api/areacliente/pe…

Mitigation only
Fix from $1,600 2025-09-25
Unclassified MEDIUM 6.5
CVE-2025-9342

Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privilege Abuse. This issue affects…

Mitigation only
Fix from $1,600 2025-09-23
Librechat MEDIUM 5.3
CVE-2025-7106

danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/…

Fix: 0.7.9+
Fix from $1,600 2025-09-23
Unclassified MEDIUM 5.5
CVE-2025-59562

Authorization Bypass Through User-Controlled Key vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Con…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.4
CVE-2025-57994

Authorization Bypass Through User-Controlled Key vulnerability in Sayful Islam Upcoming Events Lists upcoming-events-lists allows Exploiting Incorrec…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 6.5
CVE-2025-0875

Authorization Bypass Through User-Controlled Key vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Infor…

Mitigation only
Fix from $1,600 2025-09-22
Qloapps MEDIUM 5.3
CVE-2025-10759

A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula…

Fix: after 1.7.0
Fix from $1,600 2025-09-21
Mattermost Server MEDIUM 6.5
CVE-2025-9081

Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sen…

Fix: 9.11.17 / 10.5.9+
Fix from $1,600 2025-09-19
Unclassified MEDIUM 6.4
CVE-2025-8532

Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workfl…

Mitigation only
Fix from $1,600 2025-09-19
Unclassified CRITICAL 9.8
CVE-2025-5948

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0…

Mitigation only
Fix from $2,300 2025-09-19
Unclassified MEDIUM 5.3
CVE-2025-10493

The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and comple…

Mitigation only
Fix from $1,600 2025-09-18
Unclassified MEDIUM 5.3
CVE-2025-8463

Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forceful Browsing. This issue affe…

Mitigation only
Fix from $1,600 2025-09-17
Unclassified MEDIUM 6.5
CVE-2025-8057

Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Improper Authorization vulnerabili…

Mitigation only
Fix from $1,600 2025-09-16
Unclassified MEDIUM 6.5
CVE-2025-7355

Authorization Bypass Through User-Controlled Key vulnerability in Beefull Energy Technologies Beefull App allows Exploitation of Trusted Identifiers.…

Mitigation only
Fix from $1,600 2025-09-16
Unclassified MEDIUM 6.5
CVE-2025-5518

Authorization Bypass Through User-Controlled Key vulnerability with user privileges in ArgusTech BILGER allows Exploitation of Trusted Identifiers. …

Mitigation only
Fix from $1,600 2025-09-16
Digital Experience Platform HIGH 8.1
CVE-2025-43790

Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.6, 2024.Q1…

Fix: 7.4.3.124 / 2024.Q1.13+
Fix from $1,950 2025-09-11
Unclassified HIGH 8.8
CVE-2025-7718

The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all v…

Mitigation only
Fix from $1,950 2025-09-10
Unclassified HIGH 8.8
CVE-2025-7049

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 v…

Mitigation only
Fix from $1,950 2025-09-10
Unclassified HIGH 8.8
CVE-2025-52389

An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data f…

Mitigation only
Fix from $1,950 2025-09-08
Unclassified CRITICAL 9.8
CVE-2025-9114

The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0. This is due to the plugin pr…

Mitigation only
Fix from $2,300 2025-09-08
Unclassified MEDIUM 6.8
CVE-2024-13063

Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows Forceful Browsing. This issue affects MyRezzta: from s2.0…

Mitigation only
Fix from $1,600 2025-09-03
Android HIGH 7.8
CVE-2025-22422

In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be used in …

Mitigation only
Fix from $1,950 2025-09-02
System Pdv CRITICAL 9.8
CVE-2025-45968

An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contains an Ins…

Mitigation only
Fix from $2,300 2025-08-25
Reolink MEDIUM 6.5
CVE-2025-55621

An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access and download other use…

No fix yet
Fix from $1,600 2025-08-22
Unclassified MEDIUM 5.4
CVE-2025-57886

Authorization Bypass Through User-Controlled Key vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker al…

Mitigation only
Fix from $1,600 2025-08-22
Jsherp HIGH 8.8
CVE-2025-55370

Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the correspo…

No fix yet
Fix from $1,950 2025-08-21
Xxl Job MEDIUM 5.4
CVE-2025-9264

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/…

Fix: after 3.1.1
Fix from $1,600 2025-08-21
Unclassified HIGH 7.5
CVE-2025-5261

Authorization Bypass Through User-Controlled Key vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Exploitation of Trusted Identif…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 7.5
CVE-2025-53208

Authorization Bypass Through User-Controlled Key vulnerability in paymayapg Maya Business paymaya-checkout-for-woocommerce allows Accessing Functiona…

Mitigation only
Fix from $1,950 2025-08-20
Flaskblog MEDIUM 6.5
CVE-2025-55737

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every…

Fix: after 2.8.0
Fix from $1,600 2025-08-19