Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.4 CVE-2026-22398 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fleur fleur allows Exploiting Incorrectly Configured Access Control S… No fix yet Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22400 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Holmes holmes allows Exploiting Incorrectly Configured Access Control… Mitigation only Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22391 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Cocco cocco allows Exploiting Incorrectly Configured Access Control S… No fix yet Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22393 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectly Configured Access Control S… No fix yet Fix from $1,6002026-01-22 MEDIUM 5.4 CVE-2026-22396 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fiorello fiorello allows Exploiting Incorrectly Configured Access Con… Mitigation only Fix from $1,6002026-01-22 HIGH 7.4 CVE-2025-65098 Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credential… Typebot 3.13.2+ Fix from $1,9502026-01-22 HIGH 7.5 CVE-2025-10855 Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows Exploitation of Trusted Identi… Mitigation only Fix from $1,9502026-01-22 HIGH 7.5 CVE-2025-10024 Authorization Bypass Through User-Controlled Key vulnerability in EXERT Computer Technologies Software Ltd. Co. Education Management System allows Pa… Mitigation only Fix from $1,9502026-01-22 MEDIUM 5.4 CVE-2026-23964 Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object re… Mastodon 4.3.18 / 4.4.12+ Fix from $1,6002026-01-22 HIGH 8.8 CVE-2026-23754 D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can su… D View 8 after 2.0.1.107 Fix from $1,9502026-01-21 CRITICAL 9.8 CVE-2025-15521 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeove… Mitigation only Fix from $2,3002026-01-21 HIGH 7.1 CVE-2026-23843 teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients. Prior to commit dd082a134a2… Patch available Fix from $1,9502026-01-19 HIGH 7.5 CVE-2025-14844 The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 vi… Restrict Content 3.2.17+ Fix from $1,9502026-01-16 HIGH 7.5 CVE-2025-64516 GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any … Glpi 10.0.21 / 11.0.3+ Fix from $1,9502026-01-15 CRITICAL 9.8 CVE-2026-23478 Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attack… Cal.com 6.0.7+ Fix from $2,3002026-01-13 CRITICAL 10.0 CVE-2025-40805 Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to c… Mitigation only Fix from $2,3002026-01-13 HIGH 8.2 CVE-2023-36331 Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulatio… Xmall No fix yet Fix from $1,9502026-01-12 HIGH 8.1 CVE-2025-41077 IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all user… Inbox 4.5.27+ Fix from $1,9502026-01-12 HIGH 8.8 CVE-2025-69274 Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issu… Dx Netops Spectrum 24.3.11+ Fix from $1,9502026-01-12 HIGH 7.5 CVE-2026-22589 Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure … Spree 4.10.2 / 5.0.7+ Fix from $1,9502026-01-10 HIGH 7.5 CVE-2025-13457 The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get… Mitigation only Fix from $1,9502026-01-10 MEDIUM 5.9 CVE-2026-21409 Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is conducted on the communication bet… Mitigation only Fix from $1,6002026-01-09 MEDIUM 6.5 CVE-2026-22588 Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Di… Spree 4.10.2 / 5.0.7+ Fix from $1,6002026-01-08 CRITICAL 9.8 CVE-2026-22234 OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predict… Ecase Portal 9.0.45.0+ Fix from $2,3002026-01-08 HIGH 7.5 CVE-2026-22235 OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'ch… Ecase Ecomplaint 9.0.45.0+ Fix from $1,9502026-01-08 MEDIUM 5.3 CVE-2025-4596 Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging to other users through manipul… Mitigation only Fix from $1,6002026-01-08 MEDIUM 6.5 CVE-2025-67919 Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access… Mitigation only Fix from $1,6002026-01-08 CRITICAL 9.8 CVE-2025-15018 The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This… Mitigation only Fix from $2,3002026-01-07 MEDIUM 5.4 CVE-2025-14802 The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and including, 4.3.2.2 via the /wp… Mitigation only Fix from $1,6002026-01-07 CRITICAL 9.8 CVE-2020-36923 Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. … Bravia Signage after 1.7.8 Fix from $2,3002026-01-06