Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.2 CVE-2025-40541 An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute nativ… Serv U 15.5.4+ Fix from $1,9502026-02-24 MEDIUM 6.5 CVE-2026-2698 An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. Security Center 6.8.0+ Fix from $1,6002026-02-23 HIGH 8.8 CVE-2026-2697 An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. Security Center 6.8.0+ Fix from $1,9502026-02-23 MEDIUM 5.4 CVE-2026-2997 Tronclass developed by WisdomGarden has a Insecure Direct Object Reference vulnerability. After obtaining a course ID, authenticated remote attackers… Mitigation only Fix from $1,6002026-02-23 CRITICAL 9.4 CVE-2025-70833 An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administra… Smanga Mitigation only Fix from $2,3002026-02-20 HIGH 8.1 CVE-2025-15582 A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacted element is the function Delete/Update of the component Product Mana… E Commerce No fix yet Fix from $1,9502026-02-20 HIGH 7.5 CVE-2026-24950 Authorization Bypass Through User-Controlled Key vulnerability in themeplugs Authorsy authorsy allows Exploiting Incorrectly Configured Access Contro… Mitigation only Fix from $1,9502026-02-20 HIGH 7.5 CVE-2026-22383 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allow… Mitigation only Fix from $1,9502026-02-20 HIGH 7.5 CVE-2025-69394 Authorization Bypass Through User-Controlled Key vulnerability in cnvrse Cnvrse cnvrse allows Exploiting Incorrectly Configured Access Control Securi… Mitigation only Fix from $1,9502026-02-20 MEDIUM 6.5 CVE-2025-68514 Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting In… Mitigation only Fix from $1,6002026-02-20 HIGH 7.5 CVE-2025-68051 Authorization Bypass Through User-Controlled Key vulnerability in Shiprocket Shiprocket shiprocket allows Exploiting Incorrectly Configured Access Co… Mitigation only Fix from $1,9502026-02-20 HIGH 8.1 CVE-2026-26016 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization… Panel 1.12.1+ Fix from $1,9502026-02-19 HIGH 7.3 CVE-2025-9062 Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection… Mitigation only Fix from $1,9502026-02-19 MEDIUM 5.3 CVE-2026-1219 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versi… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25324 Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incor… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2026-25005 Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrect… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.3 CVE-2025-13842 The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions up to and including 7.5.0. Th… Mitigation only Fix from $1,6002026-02-19 MEDIUM 6.5 CVE-2025-70063 The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The app… Hospital Management System No fix yet Fix from $1,6002026-02-18 MEDIUM 6.5 CVE-2026-1436 Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can acces… Graylog Mitigation only Fix from $1,6002026-02-18 MEDIUM 5.4 CVE-2026-1987 The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due … Mitigation only Fix from $1,6002026-02-14 HIGH 8.3 CVE-2026-1619 Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers. … Flexcity 1.0.36+ Fix from $1,9502026-02-13 MEDIUM 6.3 CVE-2025-13004 Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Manipulating Us… E Commerce Package after 2025-11-27 Fix from $1,6002026-02-12 HIGH 8.8 CVE-2025-15096 The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and includin… Mitigation only Fix from $1,9502026-02-11 MEDIUM 5.4 CVE-2025-10912 Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Manipulating User… Mitigation only Fix from $1,6002026-02-11 HIGH 8.8 CVE-2025-7347 Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Tracking System allows Exploitation … Mitigation only Fix from $1,9502026-02-10 MEDIUM 5.7 CVE-2025-12063 An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions. Camera Station Pro 6.14.10768+ Fix from $1,6002026-02-10 HIGH 8.8 CVE-2026-25497 Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,9502026-02-09 MEDIUM 6.5 CVE-2026-24900 MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_id>/assignments/<:assignment_… Markus 2.9.1+ Fix from $1,6002026-02-09 HIGH 7.5 CVE-2026-25563 WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementatio… Wekan 8.19+ Fix from $1,9502026-02-07 HIGH 7.5 CVE-2026-25564 WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementatio… Wekan 8.19+ Fix from $1,9502026-02-07