Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.3 CVE-2025-54691 Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Exploiting Incorre… Mitigation only Fix from $1,6002025-08-14 MEDIUM 6.5 CVE-2025-8770 An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could… GitLab 18.0.6 / 18.1.4+ Fix from $1,6002025-08-13 MEDIUM 5.3 CVE-2025-3089 ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a lo… No fix yet Fix from $1,6002025-08-12 HIGH 7.8 CVE-2025-8794 A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown funct… Litmus after 3.19.0 Fix from $1,9502025-08-10 MEDIUM 5.3 CVE-2025-8755 A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberC… Mall after 1.0.3 Fix from $1,6002025-08-09 HIGH 8.8 CVE-2025-4796 The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due… Eventin 4.0.35+ Fix from $1,9502025-08-08 MEDIUM 6.5 CVE-2025-36023 IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive… Cloud Pak For Business Automation Mitigation only Fix from $1,6002025-08-08 MEDIUM 5.3 CVE-2025-51533 An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a cr… Sage Dpw 2025_06_000+ Fix from $1,6002025-08-07 HIGH 8.8 CVE-2025-46387 CWE-639 Authorization Bypass Through User-Controlled Key No fix yet Fix from $1,9502025-08-06 HIGH 8.8 CVE-2025-46386 CWE-639 Authorization Bypass Through User-Controlled Key No fix yet Fix from $1,9502025-08-06 HIGH 7.5 CVE-2025-51628 Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated at… No fix yet Fix from $1,9502025-08-05 CRITICAL 9.8 CVE-2025-5947 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including… Mitigation only Fix from $2,3002025-08-01 HIGH 8.0 CVE-2025-50849 CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through… Mitigation only Fix from $1,9502025-07-31 MEDIUM 5.4 CVE-2025-53357 GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk f… Glpi 10.0.19+ Fix from $1,6002025-07-30 HIGH 7.7 CVE-2025-53944 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external A… Autogpt Platform Patch available Fix from $1,9502025-07-30 HIGH 8.0 CVE-2025-52446 Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface … Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-07-25 HIGH 8.1 CVE-2025-52447 Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-07-25 HIGH 8.1 CVE-2025-52448 Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allo… Tableau Server 2023.3.19 / 2024.2.12+ Fix from $1,9502025-07-25 MEDIUM 5.4 CVE-2025-51479 Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary us… Onyx Patch available Fix from $1,6002025-07-22 HIGH 8.8 CVE-2025-51865 Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing at… Mitigation only Fix from $1,9502025-07-22 MEDIUM 6.5 CVE-2025-51867 Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM u… Mitigation only Fix from $1,6002025-07-22 HIGH 8.7 CVE-2025-34140 An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API en… Mitigation only Fix from $1,9502025-07-22 MEDIUM 6.0 CVE-2025-7899 The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue aff… Mitigation only Fix from $1,6002025-07-22 MEDIUM 6.5 CVE-2025-7900 The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects fema… TYPO3 after 8.3.0 Fix from $1,6002025-07-22 HIGH 8.1 CVE-2025-7947 A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component … Jsherp after 3.5 Fix from $1,9502025-07-22 HIGH 7.5 CVE-2025-51868 Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation… Mitigation only Fix from $1,9502025-07-21 HIGH 7.5 CVE-2025-51869 Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, t… Mitigation only Fix from $1,9502025-07-21 HIGH 7.5 CVE-2025-4129 Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers. This issue affects … Mitigation only Fix from $1,9502025-07-21 HIGH 7.1 CVE-2025-4040 Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation. This issue… Mitigation only Fix from $1,9502025-07-21 MEDIUM 6.5 CVE-2025-5681 Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers. This issue affe… Mitigation only Fix from $1,6002025-07-21