Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 8.8 CVE-2025-5949 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0… Mitigation only Fix from $1,9502025-11-01 MEDIUM 5.0 CVE-2025-61876 Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an authenticated user with low priv… Mitigation only Fix from $1,6002025-10-29 MEDIUM 6.5 CVE-2025-64283 Authorization Bypass Through User-Controlled Key vulnerability in Rometheme RTMKit rometheme-for-elementor allows Exploiting Incorrectly Configured A… Mitigation only Fix from $1,6002025-10-29 HIGH 8.8 CVE-2025-12288 A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the comp… Pharmacare after 9.4 Fix from $1,9502025-10-27 MEDIUM 6.8 CVE-2025-12351 Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this v… Mitigation only Fix from $1,6002025-10-27 HIGH 8.1 CVE-2025-12283 A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown function. The manipulation results… Client Details System No fix yet Fix from $1,9502025-10-27 HIGH 7.5 CVE-2025-12270 A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an unknown function of the file … Learnhouse after 2025-09-21 Fix from $1,9502025-10-27 HIGH 8.6 CVE-2025-34293 GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to t… Mitigation only Fix from $1,9502025-10-24 HIGH 8.4 CVE-2025-11957 Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-appr… Devolutions Server 2025.2.14.0+ Fix from $1,9502025-10-22 MEDIUM 6.5 CVE-2025-49952 Authorization Bypass Through User-Controlled Key vulnerability in favethemes Houzez houzez allows Exploiting Incorrectly Configured Access Control Se… Mitigation only Fix from $1,6002025-10-22 MEDIUM 5.5 CVE-2025-8884 Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of… Mitigation only Fix from $1,6002025-10-20 MEDIUM 5.3 CVE-2025-11741 The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.2.5 via t… Mitigation only Fix from $1,6002025-10-18 HIGH 7.5 CVE-2025-11517 The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to … Mitigation only Fix from $1,9502025-10-18 MEDIUM 6.5 CVE-2025-9559 Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only … Pega Platform 23.1.5+ Fix from $1,6002025-10-16 HIGH 8.2 CVE-2024-56143 Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document ser… Strapi 5.5.2+ Fix from $1,9502025-10-16 HIGH 7.5 CVE-2025-41020 Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to ot… Exito Mitigation only Fix from $1,9502025-10-16 CRITICAL 9.8 CVE-2025-10742 The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.8.6. This is due to the … Mitigation only Fix from $2,3002025-10-16 MEDIUM 5.3 CVE-2025-40773 A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnera… Sipass Integrated 3.00+ Fix from $1,6002025-10-14 HIGH 7.5 CVE-2025-9902 Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trade Co. Ltd. QRMenu allows Priv… Mitigation only Fix from $1,9502025-10-13 HIGH 7.5 CVE-2025-31997 HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access re… Unica Centralized Offer Management 25.1.0.1+ Fix from $1,9502025-10-12 MEDIUM 5.3 CVE-2025-11518 The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5… Mitigation only Fix from $1,6002025-10-11 MEDIUM 6.1 CVE-2025-8887 Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in … Mitigation only Fix from $1,6002025-10-10 HIGH 8.7 CVE-2025-61779 Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions … Patch available Fix from $1,9502025-10-09 HIGH 8.8 CVE-2025-6038 The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via p… Mitigation only Fix from $1,9502025-10-09 MEDIUM 5.3 CVE-2025-40676 Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Research Infrastructure (BBMRI-ER… Mitigation only Fix from $1,6002025-10-07 MEDIUM 6.0 CVE-2025-0606 Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing, Resource Leak Exposure. Th… Mitigation only Fix from $1,6002025-10-06 MEDIUM 6.3 CVE-2025-0642 Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Software and Consulting Ltd. Co. As… No fix yet Fix from $1,6002025-10-02 HIGH 8.1 CVE-2025-56392 An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other user… Collegetivity No fix yet Fix from $1,9502025-09-30 HIGH 7.5 CVE-2025-41098 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a  misuse of the g… Bold Workplanner 2.5.25+ Fix from $1,9502025-09-30 MEDIUM 6.5 CVE-2025-41099 Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate… Bold Workplanner 2.5.25+ Fix from $1,6002025-09-30