Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Event Tickets MEDIUM 5.3
CVE-2024-13457

The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.…

Fix: 5.18.1.1+
Fix from $1,600 2025-01-30
Coolify MEDIUM 6.5
CVE-2025-22608

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing auth…

Fix: 4.0.0+
Fix from $1,600 2025-01-24
Unclassified HIGH 8.8
CVE-2024-10497

CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those…

Mitigation only
Fix from $1,950 2025-01-17
Truefiling MEDIUM 6.3
CVE-2024-11146

TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect pu…

Fix: 3.1.112.19+
Fix from $1,600 2025-01-17
Sap Basis MEDIUM 6.5
CVE-2025-0058

In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request …

Patch available
Fix from $1,600 2025-01-14
Dryice Myxalytics HIGH 8.1
CVE-2024-42169

HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user…

Mitigation only
Fix from $1,950 2025-01-11
Wpbookit CRITICAL 9.8
CVE-2024-10215

The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin …

Fix: 1.6.6+
Fix from $2,300 2025-01-09
Unclassified MEDIUM 5.4
CVE-2024-44450

Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.

No fix yet
Fix from $1,600 2025-01-07
Unclassified HIGH 8.8
CVE-2024-13040

The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote…

Mitigation only
Fix from $1,950 2024-12-31
Unclassified MEDIUM 5.3
CVE-2024-12103

The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, an…

Mitigation only
Fix from $1,600 2024-12-24
Unclassified MEDIUM 6.5
CVE-2024-55471

Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to acc…

Patch available
Fix from $1,600 2024-12-20
Complaint Management System HIGH 8.8
CVE-2024-55506

An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obta…

No fix yet
Fix from $1,950 2024-12-18
Media Server HIGH 7.5
CVE-2024-4464

Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-33…

Fix: 1.4-2680 / 2.0.5-3152+
Fix from $1,950 2024-12-18
Unclassified MEDIUM 6.5
CVE-2024-9819

Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse. This issue affects NG Analy…

Mitigation only
Fix from $1,600 2024-12-17
Unclassified MEDIUM 5.3
CVE-2024-12309

The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and…

Mitigation only
Fix from $1,600 2024-12-13
Ujcms MEDIUM 5.9
CVE-2024-12483

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the comp…

Fix: 9.6.3+
Fix from $1,600 2024-12-12
Networker HIGH 7.5
CVE-2024-42422

Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remo…

Fix: 19.10.0.6 / 19.11.0.3+
Fix from $1,950 2024-12-03
Media Streaming Add On HIGH 8.8
CVE-2024-50395

An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability…

Fix: 500.1.1.6+
Fix from $1,950 2024-11-22
Button Block MEDIUM 6.5
CVE-2024-10671

The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to…

Fix: 1.1.5+
Fix from $1,600 2024-11-21
Sirv HIGH 8.1
CVE-2024-10855

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of serv…

Fix: 7.3.1+
Fix from $1,950 2024-11-20
Unclassified HIGH 7.5
CVE-2024-11318

An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a r…

Mitigation only
Fix from $1,950 2024-11-18
Tables MEDIUM 6.5
CVE-2024-52511

Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could b…

Fix: 0.8.0+
Fix from $1,600 2024-11-15
Java Shop MEDIUM 6.5
CVE-2024-50651

java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modify…

No fix yet
Fix from $1,600 2024-11-15
Wp Project Manager HIGH 7.3
CVE-2024-10174

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Inse…

Fix: 2.6.14+
Fix from $1,950 2024-11-13
Unclassified HIGH 7.6
CVE-2021-27700

SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner mode can switch to another cus…

Mitigation only
Fix from $1,950 2024-11-12
Fortiportal HIGH 8.1
CVE-2023-47543

An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticat…

Fix: 7.0.4+
Fix from $1,950 2024-11-12
Hospital Management System HIGH 8.1
CVE-2024-11073

A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /…

No fix yet
Fix from $1,950 2024-11-11
Unclassified MEDIUM 6.5
CVE-2024-9262

The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…

Mitigation only
Fix from $1,600 2024-11-09
Moodle HIGH 7.5
CVE-2024-43438

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users…

Fix: 4.1.12 / 4.2.9+
Fix from $1,950 2024-11-07
Aero MEDIUM 6.5
CVE-2024-51559

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could explo…

Fix: 1.1.7 / 120820241550+
Fix from $1,600 2024-11-04