Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.3 CVE-2026-25757 Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can vi… Spree 5.0.8 / 5.1.10+ Fix from $1,6002026-02-06 HIGH 7.5 CVE-2026-25758 Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow th… Spree 4.10.3 / 5.0.8+ Fix from $1,9502026-02-06 MEDIUM 5.4 CVE-2026-25574 Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vul… Payload 3.74.0+ Fix from $1,6002026-02-06 MEDIUM 5.3 CVE-2026-1271 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,… Mitigation only Fix from $1,6002026-02-05 HIGH 7.5 CVE-2026-24773 The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an Insecure Direct Object Ref… Open Eclass Platform 4.2+ Fix from $1,9502026-02-03 MEDIUM 5.3 CVE-2026-24991 Authorization Bypass Through User-Controlled Key vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allows Exploiting Incorrectly Conf… Mitigation only Fix from $1,6002026-02-03 MEDIUM 6.9 CVE-2026-1664 Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function within the Cloudflare Agents SDK.… Mitigation only Fix from $1,6002026-02-03 HIGH 8.1 CVE-2026-1375 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions u… Mitigation only Fix from $1,9502026-02-03 MEDIUM 5.3 CVE-2026-0909 The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.8.3.1. This is due to the… Mitigation only Fix from $1,6002026-02-03 HIGH 7.1 CVE-2025-69207 Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any us… Khoj 2.0.0+ Fix from $1,9502026-02-02 MEDIUM 5.4 CVE-2026-1251 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u… Mitigation only Fix from $1,6002026-01-31 HIGH 7.5 CVE-2025-36365 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 under specific configuration of cataloged remot… Db2 after 12.1.3 Fix from $1,9502026-01-30 HIGH 7.5 CVE-2020-37008 EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access adm… No fix yet Fix from $1,9502026-01-29 CRITICAL 9.8 CVE-2025-7013 Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifier… Menu Panel after 29012026 Fix from $2,3002026-01-29 MEDIUM 6.5 CVE-2025-65887 A division-by-zero vulnerability in the flow.floor_divide() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a cra… Oneflow No fix yet Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2026-24134 StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authoriz… Studiocms 0.2.0+ Fix from $1,6002026-01-28 HIGH 8.1 CVE-2026-21721 The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who… Grafana 11.6.9 / 12.0.8+ Fix from $1,9502026-01-27 MEDIUM 6.8 CVE-2025-9520 An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijac… Omada Controller 6.0+ Fix from $1,6002026-01-26 HIGH 8.5 CVE-2025-14459 A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthor… Mitigation only Fix from $1,9502026-01-26 HIGH 7.5 CVE-2026-24136 Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct… Saleor 3.20.110 / 3.21.45+ Fix from $1,9502026-01-24 MEDIUM 5.3 CVE-2026-24634 Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configur… Mitigation only Fix from $1,6002026-01-23 MEDIUM 5.4 CVE-2026-24631 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Rosebud rosebud allows Exploiting Incorrectly Configured Access Contr… No fix yet Fix from $1,6002026-01-23 MEDIUM 5.3 CVE-2026-24599 Authorization Bypass Through User-Controlled Key vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrec… Mitigation only Fix from $1,6002026-01-23 MEDIUM 6.5 CVE-2026-20904 Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings o… Gitea 1.25.4+ Fix from $1,6002026-01-22 CRITICAL 9.1 CVE-2026-20912 Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote… Gitea 1.25.4+ Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2026-20897 Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L… Gitea 1.25.4+ Fix from $2,3002026-01-22 CRITICAL 9.4 CVE-2026-1201 An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior to version 2.4.2.157 could a… Mitigation only Fix from $2,3002026-01-22 MEDIUM 6.5 CVE-2026-24379 Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Ac… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22426 Authorization Bypass Through User-Controlled Key vulnerability in Elated-Themes Sweet Jane sweetjane allows Exploiting Incorrectly Configured Access … No fix yet Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22430 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Verdure verdure allows Exploiting Incorrectly Configured Access Contr… Mitigation only Fix from $1,6002026-01-22