Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2025-52670 Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accou… Revive Adserver after 6.0.1 Fix from $1,6002025-11-20 HIGH 8.1 CVE-2025-65033 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any a… Rallly 4.5.4+ Fix from $1,9502025-11-19 HIGH 8.1 CVE-2025-65034 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerability allows any authenticated … Rallly 4.5.4+ Fix from $1,9502025-11-19 MEDIUM 6.5 CVE-2025-65028 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a… Rallly 4.5.4+ Fix from $1,6002025-11-19 HIGH 8.1 CVE-2025-65029 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a… Rallly 4.5.4+ Fix from $1,9502025-11-19 HIGH 7.1 CVE-2025-65030 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment deletion API allows any auth… Rallly 4.5.4+ Fix from $1,9502025-11-19 MEDIUM 6.5 CVE-2025-65031 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in the comment creation endpoint a… Rallly 4.5.4+ Fix from $1,6002025-11-19 MEDIUM 6.5 CVE-2025-65032 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability allows a… Rallly 4.5.4+ Fix from $1,6002025-11-19 MEDIUM 6.5 CVE-2025-65020 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability in the p… Rallly 4.5.4+ Fix from $1,6002025-11-19 CRITICAL 9.1 CVE-2025-65021 Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists i… Rallly 4.5.4+ Fix from $2,3002025-11-19 MEDIUM 5.0 CVE-2025-12766 An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) version 7.21 could allow an attacke… Athoc Mitigation only Fix from $1,6002025-11-19 MEDIUM 5.3 CVE-2025-12427 The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via… Mitigation only Fix from $1,6002025-11-19 MEDIUM 6.5 CVE-2025-63513 kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality. Hospital Management System No fix yet Fix from $1,6002025-11-18 MEDIUM 5.4 CVE-2025-12524 The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.0 due to missing … Mitigation only Fix from $1,6002025-11-18 MEDIUM 5.4 CVE-2025-63291 When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify the data being requested by t… Alteryx Server after 2022.1.1.42654 Fix from $1,6002025-11-14 HIGH 8.1 CVE-2025-8855 Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable… Mitigation only Fix from $1,9502025-11-14 HIGH 7.5 CVE-2025-64706 Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerabil… Typebot 3.13.0+ Fix from $1,9502025-11-13 MEDIUM 5.3 CVE-2025-41069 Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to access or modify unauthorize… Mitigation only Fix from $1,6002025-11-13 HIGH 8.8 CVE-2025-64523 File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Ve… Filebrowser 2.45.1+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-12903 The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wc-… Mitigation only Fix from $1,9502025-11-12 MEDIUM 5.4 CVE-2025-12126 The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0 via sever… Mitigation only Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-11532 The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.0 due to missing validatio… Mitigation only Fix from $1,6002025-11-11 MEDIUM 5.3 CVE-2025-12918 A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file /… Skuul after 2.6.5 Fix from $1,6002025-11-09 MEDIUM 5.3 CVE-2025-12353 The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for WordPress is vulnerable to un… Mitigation only Fix from $1,6002025-11-08 HIGH 8.7 CVE-2025-64431 Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direct Object Reference (IDOR) att… Patch available Fix from $1,9502025-11-07 CRITICAL 9.8 CVE-2025-58627 Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Exploiting Incorrectly Co… Mitigation only Fix from $2,3002025-11-06 HIGH 7.5 CVE-2025-63248 DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID with the ID of another quest… Dwsurvey No fix yet Fix from $1,9502025-11-05 HIGH 8.5 CVE-2025-11690 An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of … Mitigation only Fix from $1,9502025-11-04 CRITICAL 9.9 CVE-2025-0987 Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection. This issue affects CVLand: … Mitigation only Fix from $2,3002025-11-03 HIGH 8.8 CVE-2025-6574 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1… Mitigation only Fix from $1,9502025-11-01