Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-54691
Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Exploiting Incorre…
Mitigation only
MEDIUM 6.5
CVE-2025-8770
An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could…
GitLab
18.0.6 / 18.1.4+
MEDIUM 5.3
CVE-2025-3089
ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a lo…
No fix yet
HIGH 7.8
CVE-2025-8794
A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown funct…
Litmus
after 3.19.0
MEDIUM 5.3
CVE-2025-8755
A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberC…
Mall
after 1.0.3
HIGH 8.8
CVE-2025-4796
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.34. This is due…
Eventin
4.0.35+
MEDIUM 6.5
CVE-2025-36023
IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002 could allow an authenticated user to view sensitive…
Cloud Pak For Business Automation
Mitigation only
MEDIUM 5.3
CVE-2025-51533
An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access internal forms via sending a cr…
Sage Dpw
2025_06_000+
HIGH 8.8
CVE-2025-46387
CWE-639 Authorization Bypass Through User-Controlled Key
No fix yet
HIGH 8.8
CVE-2025-46386
CWE-639 Authorization Bypass Through User-Controlled Key
No fix yet
HIGH 7.5
CVE-2025-51628
Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated at…
No fix yet
CRITICAL 9.8
CVE-2025-5947
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including…
Mitigation only
HIGH 8.0
CVE-2025-50849
CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling or disabling stickers through…
Mitigation only
MEDIUM 5.4
CVE-2025-53357
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk f…
Glpi
10.0.19+
HIGH 7.7
CVE-2025-53944
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6.15 and below, the external A…
Autogpt Platform
Patch available
HIGH 8.0
CVE-2025-52446
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface …
Tableau Server
2023.3.19 / 2024.2.12+
HIGH 8.1
CVE-2025-52447
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules…
Tableau Server
2023.3.19 / 2024.2.12+
HIGH 8.1
CVE-2025-52448
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allo…
Tableau Server
2023.3.19 / 2024.2.12+
MEDIUM 5.4
CVE-2025-51479
Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated attackers to modify arbitrary us…
Onyx
Patch available
HIGH 8.8
CVE-2025-51865
Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing at…
Mitigation only
MEDIUM 6.5
CVE-2025-51867
Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM u…
Mitigation only
HIGH 8.7
CVE-2025-34140
An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API en…
Mitigation only
MEDIUM 6.0
CVE-2025-7899
The powermail extension for TYPO3 allows Insecure Direct Object Reference resulting in download of arbitrary files from the webserver. This issue aff…
Mitigation only
MEDIUM 6.5
CVE-2025-7900
The femanager extension for TYPO3 allows Insecure Direct Object Reference resulting in unauthorized modification of userdata. This issue affects fema…
TYPO3
after 8.3.0
HIGH 8.1
CVE-2025-7947
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component …
Jsherp
after 3.5
HIGH 7.5
CVE-2025-51868
Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation…
Mitigation only
HIGH 7.5
CVE-2025-51869
Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, t…
Mitigation only
HIGH 7.5
CVE-2025-4129
Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers.
This issue affects …
Mitigation only
HIGH 7.1
CVE-2025-4040
Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation.
This issue…
Mitigation only
MEDIUM 6.5
CVE-2025-5681
Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers.
This issue affe…
Mitigation only