Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.3 CVE-2025-10947 A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of the file /api/areacliente/pe… Mitigation only Fix from $1,6002025-09-25 MEDIUM 6.5 CVE-2025-9342 Authorization Bypass Through User-Controlled Key vulnerability in Anadolu Hayat Emeklilik Inc. AHE Mobile allows Privilege Abuse. This issue affects… Mitigation only Fix from $1,6002025-09-23 MEDIUM 5.3 CVE-2025-7106 danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/… Librechat 0.7.9+ Fix from $1,6002025-09-23 MEDIUM 5.5 CVE-2025-59562 Authorization Bypass Through User-Controlled Key vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Con… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.4 CVE-2025-57994 Authorization Bypass Through User-Controlled Key vulnerability in Sayful Islam Upcoming Events Lists upcoming-events-lists allows Exploiting Incorrec… Mitigation only Fix from $1,6002025-09-22 MEDIUM 6.5 CVE-2025-0875 Authorization Bypass Through User-Controlled Key vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Infor… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.3 CVE-2025-10759 A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula… Qloapps after 1.7.0 Fix from $1,6002025-09-21 MEDIUM 6.5 CVE-2025-9081 Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sen… Mattermost Server 9.11.17 / 10.5.9+ Fix from $1,6002025-09-19 MEDIUM 6.4 CVE-2025-8532 Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workfl… Mitigation only Fix from $1,6002025-09-19 CRITICAL 9.8 CVE-2025-5948 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0… Mitigation only Fix from $2,3002025-09-19 MEDIUM 5.3 CVE-2025-10493 The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via the quiz submission and comple… Mitigation only Fix from $1,6002025-09-18 MEDIUM 5.3 CVE-2025-8463 Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forceful Browsing. This issue affe… Mitigation only Fix from $1,6002025-09-17 MEDIUM 6.5 CVE-2025-8057 Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Improper Authorization vulnerabili… Mitigation only Fix from $1,6002025-09-16 MEDIUM 6.5 CVE-2025-7355 Authorization Bypass Through User-Controlled Key vulnerability in Beefull Energy Technologies Beefull App allows Exploitation of Trusted Identifiers.… Mitigation only Fix from $1,6002025-09-16 MEDIUM 6.5 CVE-2025-5518 Authorization Bypass Through User-Controlled Key vulnerability with user privileges in ArgusTech BILGER allows Exploitation of Trusted Identifiers. … Mitigation only Fix from $1,6002025-09-16 HIGH 8.1 CVE-2025-43790 Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.6, 2024.Q1… Digital Experience Platform 7.4.3.124 / 2024.Q1.13+ Fix from $1,9502025-09-11 HIGH 8.8 CVE-2025-7718 The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all v… Mitigation only Fix from $1,9502025-09-10 HIGH 8.8 CVE-2025-7049 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 v… Mitigation only Fix from $1,9502025-09-10 HIGH 8.8 CVE-2025-52389 An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data f… Mitigation only Fix from $1,9502025-09-08 CRITICAL 9.8 CVE-2025-9114 The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0. This is due to the plugin pr… Mitigation only Fix from $2,3002025-09-08 MEDIUM 6.8 CVE-2024-13063 Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft MyRezzta allows Forceful Browsing. This issue affects MyRezzta: from s2.0… Mitigation only Fix from $1,6002025-09-03 HIGH 7.8 CVE-2025-22422 In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app when its result will be used in … Android Mitigation only Fix from $1,9502025-09-02 CRITICAL 9.8 CVE-2025-45968 An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contains an Ins… System Pdv Mitigation only Fix from $2,3002025-08-25 MEDIUM 6.5 CVE-2025-55621 An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access and download other use… Reolink No fix yet Fix from $1,6002025-08-22 MEDIUM 5.4 CVE-2025-57886 Authorization Bypass Through User-Controlled Key vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker al… Mitigation only Fix from $1,6002025-08-22 HIGH 8.8 CVE-2025-55370 Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the correspo… Jsherp No fix yet Fix from $1,9502025-08-21 MEDIUM 5.4 CVE-2025-9264 A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/… Xxl Job after 3.1.1 Fix from $1,6002025-08-21 HIGH 7.5 CVE-2025-5261 Authorization Bypass Through User-Controlled Key vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Exploitation of Trusted Identif… Mitigation only Fix from $1,9502025-08-20 HIGH 7.5 CVE-2025-53208 Authorization Bypass Through User-Controlled Key vulnerability in paymayapg Maya Business paymaya-checkout-for-woocommerce allows Accessing Functiona… Mitigation only Fix from $1,9502025-08-20 MEDIUM 6.5 CVE-2025-55737 flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every… Flaskblog after 2.8.0 Fix from $1,6002025-08-19