Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified MEDIUM 5.3
CVE-2025-54691

Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Exploiting Incorre…

Mitigation only
Fix from $1,600 2025-08-14
GitLab MEDIUM 6.5
CVE-2025-8770

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could…

Fix: 18.0.6 / 18.1.4+
Fix from $1,600 2025-08-13
Unclassified MEDIUM 5.3
CVE-2025-3089

ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a lo…

No fix yet
Fix from $1,600 2025-08-12
Litmus HIGH 7.8
CVE-2025-8794

A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown funct…

Fix: after 3.19.0
Fix from $1,950 2025-08-10
Mall MEDIUM 5.3
CVE-2025-8755

A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberC…

Fix: after 1.0.3
Fix from $1,600 2025-08-09
Eventin HIGH 8.8
CVE-2025-4796

The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due…

Fix: 4.0.35+
Fix from $1,950 2025-08-08
Cloud Pak For Business Automation MEDIUM 6.5
CVE-2025-36023

IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive…

Mitigation only
Fix from $1,600 2025-08-08
Sage Dpw MEDIUM 5.3
CVE-2025-51533

An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a cr…

Fix: 2025_06_000+
Fix from $1,600 2025-08-07
Unclassified HIGH 8.8
CVE-2025-46387

CWE-639 Authorization Bypass Through User-Controlled Key

No fix yet
Fix from $1,950 2025-08-06
Unclassified HIGH 8.8
CVE-2025-46386

CWE-639 Authorization Bypass Through User-Controlled Key

No fix yet
Fix from $1,950 2025-08-06
Unclassified HIGH 7.5
CVE-2025-51628

Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated at…

No fix yet
Fix from $1,950 2025-08-05
Unclassified CRITICAL 9.8
CVE-2025-5947

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including…

Mitigation only
Fix from $2,300 2025-08-01
Unclassified HIGH 8.0
CVE-2025-50849

CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through…

Mitigation only
Fix from $1,950 2025-07-31
Glpi MEDIUM 5.4
CVE-2025-53357

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk f…

Fix: 10.0.19+
Fix from $1,600 2025-07-30
Autogpt Platform HIGH 7.7
CVE-2025-53944

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external A…

Patch available
Fix from $1,950 2025-07-30
Tableau Server HIGH 8.0
CVE-2025-52446

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface …

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,950 2025-07-25
Tableau Server HIGH 8.1
CVE-2025-52447

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,950 2025-07-25
Tableau Server HIGH 8.1
CVE-2025-52448

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allo…

Fix: 2023.3.19 / 2024.2.12+
Fix from $1,950 2025-07-25
Onyx MEDIUM 5.4
CVE-2025-51479

Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary us…

Patch available
Fix from $1,600 2025-07-22
Unclassified HIGH 8.8
CVE-2025-51865

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing at…

Mitigation only
Fix from $1,950 2025-07-22
Unclassified MEDIUM 6.5
CVE-2025-51867

Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM u…

Mitigation only
Fix from $1,600 2025-07-22
Unclassified HIGH 8.7
CVE-2025-34140

An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API en…

Mitigation only
Fix from $1,950 2025-07-22
Unclassified MEDIUM 6.0
CVE-2025-7899

The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue aff…

Mitigation only
Fix from $1,600 2025-07-22
TYPO3 MEDIUM 6.5
CVE-2025-7900

The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects fema…

Fix: after 8.3.0
Fix from $1,600 2025-07-22
Jsherp HIGH 8.1
CVE-2025-7947

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component …

Fix: after 3.5
Fix from $1,950 2025-07-22
Unclassified HIGH 7.5
CVE-2025-51868

Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation…

Mitigation only
Fix from $1,950 2025-07-21
Unclassified HIGH 7.5
CVE-2025-51869

Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, t…

Mitigation only
Fix from $1,950 2025-07-21
Unclassified HIGH 7.5
CVE-2025-4129

Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers. This issue affects …

Mitigation only
Fix from $1,950 2025-07-21
Unclassified HIGH 7.1
CVE-2025-4040

Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation. This issue…

Mitigation only
Fix from $1,950 2025-07-21
Unclassified MEDIUM 6.5
CVE-2025-5681

Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers. This issue affe…

Mitigation only
Fix from $1,600 2025-07-21