Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 7.5
CVE-2025-1469

Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers. This issue affe…

Mitigation only
Fix from $1,950 2025-07-21
Unclassified MEDIUM 5.5
CVE-2024-13175

Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. This issue affects VOC TESTER:…

Mitigation only
Fix from $1,600 2025-07-18
Indico MEDIUM 6.5
CVE-2025-53640

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to…

Fix: 3.3.7+
Fix from $1,600 2025-07-14
Support Board CRITICAL 9.8
CVE-2025-4855

The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in …

Fix: 3.8.1+
Fix from $2,300 2025-07-09
Incontrol Web HIGH 8.8
CVE-2025-6765

A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the…

Mitigation only
Fix from $1,950 2025-06-27
Computer Vision Annotation Tool MEDIUM 6.5
CVE-2025-49135

CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the i…

Fix: 2.40.0+
Fix from $1,600 2025-06-25
Online Dj Booking Management System MEDIUM 6.5
CVE-2025-50693

PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/request-details.php.

No fix yet
Fix from $1,600 2025-06-24
Unclassified HIGH 7.5
CVE-2025-3091

An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s pa…

Mitigation only
Fix from $1,950 2025-06-24
Novel Plus MEDIUM 6.8
CVE-2025-6534

A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the …

Fix: after 5.1.3
Fix from $1,600 2025-06-24
Unclassified MEDIUM 5.3
CVE-2025-49995

Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Co…

Mitigation only
Fix from $1,600 2025-06-20
Real Estate Management System HIGH 8.1
CVE-2025-6329

A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown process…

No fix yet
Fix from $1,950 2025-06-20
Dm Corporative Cms HIGH 7.5
CVE-2025-40658

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the pr…

Fix: 2025.01+
Fix from $1,950 2025-06-10
Dm Corporative Cms HIGH 7.5
CVE-2025-40659

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the pr…

Fix: 2025.01+
Fix from $1,950 2025-06-10
Dm Corporative Cms HIGH 7.5
CVE-2025-40660

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the pr…

Fix: 2025.01+
Fix from $1,950 2025-06-10
Dm Corporative Cms HIGH 7.5
CVE-2025-40661

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the pr…

Fix: 2025.01+
Fix from $1,950 2025-06-10
Easync MEDIUM 5.3
CVE-2025-4691

The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Referen…

Fix: 1.3.22+
Fix from $1,600 2025-05-31
Unclassified HIGH 8.7
CVE-2025-40650

Insecure Direct Object Reference (IDOR) vulnerability in Clickedu. This vulnerability could allow an attacker to retrieve information about student r…

Mitigation only
Fix from $1,950 2025-05-26
Vacation Rental Management Platform HIGH 7.5
CVE-2025-5182

A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability a…

Fix: 1.0.2+
Fix from $1,950 2025-05-26
Itop MEDIUM 5.0
CVE-2025-24969

iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID …

Fix: 3.2.1+
Fix from $1,600 2025-05-14
Itop MEDIUM 6.5
CVE-2024-52601

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have rea…

Fix: 2.7.12 / 3.1.3+
Fix from $1,600 2025-05-14
Unclassified MEDIUM 5.3
CVE-2025-3769

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver…

Mitigation only
Fix from $1,600 2025-05-14
Unclassified MEDIUM 5.3
CVE-2024-8988

The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 vi…

Mitigation only
Fix from $1,600 2025-05-14
Unclassified CRITICAL 9.8
CVE-2025-3605EPSS 7%

The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and…

Mitigation only
Fix from $2,300 2025-05-09
Wpbookit CRITICAL 9.8
CVE-2025-3810

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due…

Fix: 1.0.3+
Fix from $2,300 2025-05-09
Wpbookit CRITICAL 9.8
CVE-2025-3811

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due…

Fix: 1.0.3+
Fix from $2,300 2025-05-09
Unclassified MEDIUM 6.5
CVE-2025-3853

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.6.0 via the callback_generate…

Mitigation only
Fix from $1,600 2025-05-07
Unclassified MEDIUM 5.3
CVE-2025-3281

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Obj…

Mitigation only
Fix from $1,600 2025-05-06
Unclassified HIGH 8.8
CVE-2025-3610

The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This …

Mitigation only
Fix from $1,950 2025-05-06
Unclassified HIGH 7.3
CVE-2025-4210

A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers…

Patch available
Fix from $1,950 2025-05-02
Wordpress Simple Paypal Shopping Cart MEDIUM 6.5
CVE-2025-3874

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3…

Fix: 5.1.4+
Fix from $1,600 2025-05-01