Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Wordpress Simple Paypal Shopping Cart MEDIUM 5.3
CVE-2025-3889

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3…

Fix: 5.1.4+
Fix from $1,600 2025-05-01
Mall HIGH 7.5
CVE-2025-4119

A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the compon…

Mitigation only
Fix from $1,950 2025-04-30
Moodle HIGH 7.1
CVE-2025-3625

A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from…

Fix: 4.3.12 / 4.4.8+
Fix from $1,950 2025-04-25
Bus Ticket Booking System HIGH 8.0
CVE-2025-25777

Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the …

No fix yet
Fix from $1,950 2025-04-24
Unclassified CRITICAL 9.3
CVE-2025-42605

This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for the initiation, modification,…

Mitigation only
Fix from $2,300 2025-04-23
Unclassified HIGH 7.0
CVE-2025-3519

An authorization bypass in Unblu Spark allows a participant of a conversation to replace an existing, uploaded file. Every uploaded file in Unblu ge…

Mitigation only
Fix from $1,950 2025-04-22
Cloud Portal MEDIUM 5.3
CVE-2025-31147

Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal HIGH 7.5
CVE-2025-31360

Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.

Fix: after 3.6.0
Fix from $1,950 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-31654

An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-31945

An unauthenticated attacker can obtain other users' charger information.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-31950

An unauthenticated attacker can obtain EV charger energy consumption information of other users.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-30257

Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-27719

Unauthenticated attackers can query an API endpoint and get device details.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-27927

An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-27929

Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-27575

An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-27561

Unauthenticated attackers can rename "rooms" of arbitrary users.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-27565

An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-26857

Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-24315

Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-24850

An attacker can export other users' plant information.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 6.5
CVE-2025-25276

An unauthenticated attacker can hijack other users' devices and potentially control them.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-31933

An unauthenticated attacker can check the existence of usernames in the system by querying an API.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-31941

An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-31949

An authenticated attacker can obtain any plant name by knowing the plant ID.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-31357

An unauthenticated attacker can obtain a user's plant list by knowing the username.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-30514

Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-30254

An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-27568

An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-27938

Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").

Fix: after 3.6.0
Fix from $1,600 2025-04-15