Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
CRITICAL 9.8 CVE-2025-15001 The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.… Mitigation only Fix from $2,3002026-01-06 CRITICAL 9.8 CVE-2025-14996 The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up… Mitigation only Fix from $2,3002026-01-06 HIGH 8.6 CVE-2025-68044 Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploit… Mitigation only Fix from $1,9502026-01-05 HIGH 7.1 CVE-2026-21447 Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer orde… Bagisto 2.3.10+ Fix from $1,9502026-01-02 CRITICAL 9.8 CVE-2025-14998 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due … Mitigation only Fix from $2,3002026-01-02 MEDIUM 5.3 CVE-2025-49334 Authorization Bypass Through User-Controlled Key vulnerability in Eduardo Villão MyD Delivery myd-delivery allows Exploiting Incorrectly Configured A… No fix yet Fix from $1,6002025-12-31 MEDIUM 5.3 CVE-2025-63053 Authorization Bypass Through User-Controlled Key vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Exploiting Incorrectl… Mitigation only Fix from $1,6002025-12-31 MEDIUM 5.4 CVE-2025-69029 Authorization Bypass Through User-Controlled Key vulnerability in Select-Themes Struktur struktur allows Exploiting Incorrectly Configured Access Con… Mitigation only Fix from $1,6002025-12-30 MEDIUM 5.4 CVE-2025-69030 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Conf… Backpack Traveler after 2.10.3 Fix from $1,6002025-12-30 MEDIUM 5.4 CVE-2025-69032 Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Incorrectly Configured Access Con… Fivestar after 1.7 Fix from $1,6002025-12-30 MEDIUM 5.3 CVE-2025-68997 Authorization Bypass Through User-Controlled Key vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Co… Mitigation only Fix from $1,6002025-12-30 MEDIUM 5.3 CVE-2025-68979 Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Inco… Mitigation only Fix from $1,6002025-12-30 MEDIUM 6.5 CVE-2025-69202 Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth token… Axios Cache Interceptor 1.11.1+ Fix from $1,6002025-12-29 CRITICAL 9.8 CVE-2019-25235 Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages b… Mitigation only Fix from $2,3002025-12-24 HIGH 7.5 CVE-2018-25129 SOCA Access Control System 180612 contains multiple insecure direct object reference vulnerabilities that allow attackers to access sensitive user cr… No fix yet Fix from $1,9502025-12-24 HIGH 7.5 CVE-2025-67909 Authorization Bypass Through User-Controlled Key vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Exploiting I… Mitigation only Fix from $1,9502025-12-24 HIGH 8.8 CVE-2021-47721 Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manip… Orangescrum No fix yet Fix from $1,9502025-12-23 CRITICAL 9.8 CVE-2023-53955 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and acces… Stream Extension Mitigation only Fix from $2,3002025-12-22 MEDIUM 6.5 CVE-2025-66911 Turms IM Server v0.10.0-SNAPSHOT and earlier contains a broken access control vulnerability in the user online status query functionality. The handle… Turms No fix yet Fix from $1,6002025-12-19 MEDIUM 5.3 CVE-2025-63043 Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly … Mitigation only Fix from $1,6002025-12-18 HIGH 7.5 CVE-2025-1031 Authorization Bypass Through User-Controlled Key vulnerability in Utarit Informatics Services Inc. SoliClub allows Functionality Misuse. This issue … Soliclub 5.3.7+ Fix from $1,9502025-12-18 CRITICAL 9.3 CVE-2025-10910 A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online Govee device to the attacker… Mitigation only Fix from $2,3002025-12-18 MEDIUM 6.5 CVE-2025-10019 Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly C… Mitigation only Fix from $1,6002025-12-18 HIGH 7.5 CVE-2023-53930 ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manip… Projectsend No fix yet Fix from $1,9502025-12-17 CRITICAL 9.8 CVE-2023-53914 UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in … Ulicms Mitigation only Fix from $2,3002025-12-17 HIGH 8.8 CVE-2025-34436 AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object… Avideo 20.0+ Fix from $1,9502025-12-17 HIGH 8.8 CVE-2025-34437 AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentic… Avideo 20.0+ Fix from $1,9502025-12-17 HIGH 8.1 CVE-2025-34438 AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation… Avideo 20.0+ Fix from $1,9502025-12-17 MEDIUM 6.5 CVE-2025-34435 AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files b… Avideo 20.0+ Fix from $1,6002025-12-17 CRITICAL 9.8 CVE-2025-67165 An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges. Pagekit Mitigation only Fix from $2,3002025-12-17