Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Cloud Portal HIGH 7.5
CVE-2025-27939

An attacker can change registered email addresses of other users and take over arbitrary accounts.

Fix: after 3.6.0
Fix from $1,950 2025-04-15
Cloud Portal MEDIUM 5.3
CVE-2025-24487

An unauthenticated attacker can infer the existence of usernames in the system by querying an API.

Fix: after 3.6.0
Fix from $1,600 2025-04-15
Unclassified HIGH 8.7
CVE-2025-3574

Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via …

Mitigation only
Fix from $1,950 2025-04-15
Unclassified HIGH 8.7
CVE-2025-3575

Insecure Direct Object Reference vulnerability in Deporsite from T-INNOVA allows an attacker to retrieve sensitive information from others users via …

Mitigation only
Fix from $1,950 2025-04-15
Employee Management System MEDIUM 6.5
CVE-2025-3536

A vulnerability was found in Tutorials-Website Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown func…

No fix yet
Fix from $1,600 2025-04-13
Employee Management System MEDIUM 5.3
CVE-2025-3537

A vulnerability was found in Tutorials-Website Employee Management System 1.0. It has been classified as critical. This affects an unknown part of th…

No fix yet
Fix from $1,600 2025-04-13
User Registration \& Membership MEDIUM 5.3
CVE-2025-3282

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Obj…

Fix: 4.1.4+
Fix from $1,600 2025-04-12
Dotnetnuke MEDIUM 6.5
CVE-2025-32373

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered u…

Fix: 9.13.8+
Fix from $1,600 2025-04-09
Unclassified HIGH 8.8
CVE-2025-2526

The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.2. This is due …

Mitigation only
Fix from $1,950 2025-04-08
Opensis HIGH 7.5
CVE-2025-22931

An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to acce…

Fix: after 9.1
Fix from $1,950 2025-04-03
Js Job Manager MEDIUM 5.4
CVE-2025-31867

Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager js-jobs allows Exploiting Incorrectly Configured Access Cont…

Fix: after 2.0.2
Fix from $1,600 2025-04-01
Np Quote Request For Woocommerce MEDIUM 5.3
CVE-2024-13558

The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9…

Fix: 1.9.180+
Fix from $1,600 2025-03-20
Unclassified MEDIUM 6.5
CVE-2024-9617

An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the…

Mitigation only
Fix from $1,600 2025-03-20
Chuanhuchatgpt HIGH 8.8
CVE-2024-8613

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue a…

Patch available
Fix from $1,950 2025-03-20
Ragflow MEDIUM 6.5
CVE-2024-12880

A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from th…

No fix yet
Fix from $1,600 2025-03-20
Superagi HIGH 8.8
CVE-2024-12048

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly che…

No fix yet
Fix from $1,950 2025-03-20
Librechat MEDIUM 5.3
CVE-2024-11167

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts v…

Fix: 0.7.6+
Fix from $1,600 2025-03-20
Lunary MEDIUM 6.5
CVE-2024-11300

In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This i…

Fix: 1.6.3+
Fix from $1,600 2025-03-20
Lunary HIGH 7.5
CVE-2024-11137

An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vu…

Fix: 1.6.1+
Fix from $1,950 2025-03-20
Librechat MEDIUM 6.5
CVE-2024-10366

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpo…

Patch available
Fix from $1,600 2025-03-20
Omnipress MEDIUM 6.5
CVE-2024-13407

The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via the megamenu block due to in…

Fix: 1.5.5+
Fix from $1,600 2025-03-14
Jobcareer CRITICAL 9.8
CVE-2024-11284

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due…

Fix: after 7.1
Fix from $2,300 2025-03-14
Jobcareer CRITICAL 9.8
CVE-2024-11285

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due…

Fix: after 7.1
Fix from $2,300 2025-03-14
Esp Idf HIGH 8.8
CVE-2024-53406

Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the s…

No fix yet
Fix from $1,950 2025-03-13
Unclassified HIGH 7.7
CVE-2025-2271

A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insec…

Mitigation only
Fix from $1,950 2025-03-13
Unclassified MEDIUM 5.3
CVE-2024-13887

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

Mitigation only
Fix from $1,600 2025-03-13
Unclassified MEDIUM 6.5
CVE-2025-0337

ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability,…

Mitigation only
Fix from $1,600 2025-03-06
Unclassified HIGH 7.6
CVE-2024-11216

Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik On…

Mitigation only
Fix from $1,950 2025-03-05
Zitadel CRITICAL 9.0
CVE-2025-27507

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains In…

Fix: 2.63.8 / 2.64.5+
Fix from $2,300 2025-03-04
Student Affairs Information System HIGH 7.5
CVE-2024-8261

Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Securit…

Fix: 24.0927+
Fix from $1,950 2025-03-03