Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Jobcareer CRITICAL 9.8
CVE-2024-11284

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due…

Fix: after 7.1
Fix from $2,300 2025-03-14
Jobcareer CRITICAL 9.8
CVE-2024-11285

The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due…

Fix: after 7.1
Fix from $2,300 2025-03-14
Esp Idf HIGH 8.8
CVE-2024-53406

Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the s…

No fix yet
Fix from $1,950 2025-03-13
Unclassified HIGH 7.7
CVE-2025-2271

A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insec…

Mitigation only
Fix from $1,950 2025-03-13
Unclassified MEDIUM 5.3
CVE-2024-13887

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

Mitigation only
Fix from $1,600 2025-03-13
Unclassified MEDIUM 6.5
CVE-2025-0337

ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability,…

Mitigation only
Fix from $1,600 2025-03-06
Unclassified HIGH 7.6
CVE-2024-11216

Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik On…

Mitigation only
Fix from $1,950 2025-03-05
Zitadel CRITICAL 9.0
CVE-2025-27507

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains In…

Fix: 2.63.8 / 2.64.5+
Fix from $2,300 2025-03-04
Student Affairs Information System HIGH 7.5
CVE-2024-8261

Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Securit…

Fix: 24.0927+
Fix from $1,950 2025-03-03
GitLab MEDIUM 5.3
CVE-2024-10925

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to …

Fix: 17.7.6 / 17.8.4+
Fix from $1,600 2025-03-03
Academia Student Information System MEDIUM 6.5
CVE-2025-25952

An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student In…

Mitigation only
Fix from $1,600 2025-03-03
Isolarcloud CRITICAL 9.1
CVE-2024-50685

SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService AP…

Fix: 2024-10-31+
Fix from $2,300 2025-02-26
Isolarcloud CRITICAL 9.1
CVE-2024-50686

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model.

Fix: 2024-10-31+
Fix from $2,300 2025-02-26
Isolarcloud CRITICAL 9.1
CVE-2024-50687

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService API model.

Fix: 2024-10-31+
Fix from $2,300 2025-02-26
Isolarcloud CRITICAL 9.1
CVE-2024-50689

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model.

Fix: 2024-10-31+
Fix from $2,300 2025-02-26
Isolarcloud CRITICAL 9.1
CVE-2024-50693

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.

Fix: 2024-10-31+
Fix from $2,300 2025-02-26
Filebird HIGH 7.2
CVE-2025-26977

Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Contro…

Fix: 6.4.6+
Fix from $1,950 2025-02-25
Unclassified MEDIUM 5.3
CVE-2025-26965

Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access …

Mitigation only
Fix from $1,600 2025-02-25
Ragflow HIGH 8.1
CVE-2025-25282

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Ins…

Fix: 0.14.1+
Fix from $1,950 2025-02-21
Unclassified HIGH 7.5
CVE-2025-0352

Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing …

Mitigation only
Fix from $1,950 2025-02-20
Peprodev Ultimate Invoice MEDIUM 5.3
CVE-2024-13719

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via …

Fix: after 2.0.8
Fix from $1,600 2025-02-19
Unclassified HIGH 8.4
CVE-2025-26788

StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.

Mitigation only
Fix from $1,950 2025-02-14
Return Refund And Exchange For Woocommerce MEDIUM 5.4
CVE-2024-13692

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vul…

Fix: 4.4.6+
Fix from $1,600 2025-02-14
H6web HIGH 7.1
CVE-2025-1270

Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by …

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 8.8
CVE-2024-34520

An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authe…

Mitigation only
Fix from $1,950 2025-02-12
Unclassified MEDIUM 6.6
CVE-2025-24976

Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with…

Patch available
Fix from $1,600 2025-02-11
Unclassified HIGH 7.5
CVE-2024-39033

In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII t…

Mitigation only
Fix from $1,950 2025-02-06
Wp Job Portal MEDIUM 5.3
CVE-2024-13372

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Refer…

Fix: 2.2.7+
Fix from $1,600 2025-02-01
Wp Job Portal MEDIUM 5.3
CVE-2024-13428

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Refer…

Fix: 2.2.7+
Fix from $1,600 2025-02-01
Woocommerce Wishlist HIGH 7.5
CVE-2024-13694

The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direc…

Fix: 1.8.8+
Fix from $1,950 2025-01-30