Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.1 CVE-2025-14101 Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploitation of Trusted Identifiers… Mitigation only Fix from $1,9502025-12-17 HIGH 7.5 CVE-2025-11924 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up … Ninja Forms 3.13.1+ Fix from $1,9502025-12-17 HIGH 7.5 CVE-2025-13474 Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation of Trusted Identifiers. This … Mitigation only Fix from $1,9502025-12-16 MEDIUM 6.5 CVE-2025-68071 Authorization Bypass Through User-Controlled Key vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly C… Mitigation only Fix from $1,6002025-12-16 MEDIUM 5.3 CVE-2025-67985 Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-lite allows Exploiting Incorre… Mitigation only Fix from $1,6002025-12-16 MEDIUM 5.3 CVE-2025-66132 Authorization Bypass Through User-Controlled Key vulnerability in FAPI Business s.r.o. FAPI Member fapi-member allows Exploiting Incorrectly Configur… No fix yet Fix from $1,6002025-12-16 HIGH 8.1 CVE-2025-58137 Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is … Fineract 1.12.1+ Fix from $1,9502025-12-12 MEDIUM 5.3 CVE-2025-12883 The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2… Mitigation only Fix from $1,6002025-12-12 HIGH 7.6 CVE-2025-13124 Authorization Bypass Through User-Controlled Key vulnerability in Netiket Information Technologies Ltd. Co. ApplyLogic allows Exploitation of Trusted… No fix yet Fix from $1,9502025-12-11 HIGH 7.6 CVE-2025-13003 Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard allows Exploitation of Truste… Mitigation only Fix from $1,9502025-12-11 HIGH 7.5 CVE-2020-36895 EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access … I Media Server Digital Signage No fix yet Fix from $1,9502025-12-10 HIGH 8.3 CVE-2025-41358 Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authe… Mitigation only Fix from $1,9502025-12-10 MEDIUM 5.3 CVE-2025-63065 Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Exploiting Inc… Mitigation only Fix from $1,6002025-12-09 HIGH 8.1 CVE-2025-61075 Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users … Mitarbeiter Portal 2.16.1+ Fix from $1,9502025-12-09 MEDIUM 6.5 CVE-2025-64497 Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.1762431347 of Tuleap Community Editi… Tuleap 16.12-10 / 16.13-7+ Fix from $1,6002025-12-08 MEDIUM 5.3 CVE-2025-13748 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje… Mitigation only Fix from $1,6002025-12-06 MEDIUM 5.3 CVE-2025-66513 Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric… Tables 0.8.9 / 0.9.6+ Fix from $1,6002025-12-05 HIGH 8.3 CVE-2025-13932 The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference (IDOR), where any authenticat… Mitigation only Fix from $1,9502025-12-04 MEDIUM 6.5 CVE-2025-61148 An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other st… Edupluscampus No fix yet Fix from $1,6002025-12-04 MEDIUM 6.5 CVE-2025-65097 RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4… Romm 4.4.1+ Fix from $1,6002025-12-03 MEDIUM 6.5 CVE-2025-41086 Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be generated, bypassing any usage res… Gams 48.7.0 / 49.7.0+ Fix from $1,6002025-12-02 MEDIUM 6.5 CVE-2025-66306 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Pa… Grav 1.8.0+ Fix from $1,6002025-12-01 CRITICAL 9.8 CVE-2025-13615 The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the p… Mitigation only Fix from $2,3002025-11-30 HIGH 8.8 CVE-2025-13768 WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by … Webitr 2_1_0_34+ Fix from $1,9502025-11-28 MEDIUM 5.3 CVE-2025-13157 The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 … Mitigation only Fix from $1,6002025-11-27 HIGH 7.5 CVE-2025-65672 Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings. Classroomio No fix yet Fix from $1,9502025-11-26 MEDIUM 5.3 CVE-2025-64067 Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to im… Project Contract Management Mitigation only Fix from $1,6002025-11-25 MEDIUM 5.3 CVE-2025-13389 The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a mi… Mitigation only Fix from $1,6002025-11-25 MEDIUM 6.5 CVE-2025-12040 The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.3 via s… Mitigation only Fix from $1,6002025-11-25 MEDIUM 5.4 CVE-2025-12881 The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl… Mitigation only Fix from $1,6002025-11-21