Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.5 CVE-2025-1469 Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers. This issue affe… Mitigation only Fix from $1,9502025-07-21 MEDIUM 5.5 CVE-2024-13175 Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. This issue affects VOC TESTER:… Mitigation only Fix from $1,6002025-07-18 MEDIUM 6.5 CVE-2025-53640 Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to… Indico 3.3.7+ Fix from $1,6002025-07-14 CRITICAL 9.8 CVE-2025-4855 The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in … Support Board 3.8.1+ Fix from $2,3002025-07-09 HIGH 8.8 CVE-2025-6765 A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the… Incontrol Web Mitigation only Fix from $1,9502025-06-27 MEDIUM 6.5 CVE-2025-49135 CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.2.0 through 2.39.0 have no validation during the i… Computer Vision Annotation Tool 2.40.0+ Fix from $1,6002025-06-25 MEDIUM 6.5 CVE-2025-50693 PHPGurukul Online DJ Booking Management System 2.0 is vulnerable to Insecure Direct Object Reference (IDOR) in odms/request-details.php. Online Dj Booking Management System No fix yet Fix from $1,6002025-06-24 HIGH 7.5 CVE-2025-3091 An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s pa… Mitigation only Fix from $1,9502025-06-24 MEDIUM 6.8 CVE-2025-6534 A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the … Novel Plus after 5.1.3 Fix from $1,6002025-06-24 MEDIUM 5.3 CVE-2025-49995 Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Co… Mitigation only Fix from $1,6002025-06-20 HIGH 8.1 CVE-2025-6329 A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown process… Real Estate Management System No fix yet Fix from $1,9502025-06-20 HIGH 7.5 CVE-2025-40658 An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the pr… Dm Corporative Cms 2025.01+ Fix from $1,9502025-06-10 HIGH 7.5 CVE-2025-40659 An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the pr… Dm Corporative Cms 2025.01+ Fix from $1,9502025-06-10 HIGH 7.5 CVE-2025-40660 An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the pr… Dm Corporative Cms 2025.01+ Fix from $1,9502025-06-10 HIGH 7.5 CVE-2025-40661 An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the pr… Dm Corporative Cms 2025.01+ Fix from $1,9502025-06-10 MEDIUM 5.3 CVE-2025-4691 The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to Insecure Direct Object Referen… Easync 1.3.22+ Fix from $1,6002025-05-31 HIGH 8.7 CVE-2025-40650 Insecure Direct Object Reference (IDOR) vulnerability in Clickedu. This vulnerability could allow an attacker to retrieve information about student r… Mitigation only Fix from $1,9502025-05-26 HIGH 7.5 CVE-2025-5182 A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability a… Vacation Rental Management Platform 1.0.2+ Fix from $1,9502025-05-26 MEDIUM 5.0 CVE-2025-24969 iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID … Itop 3.2.1+ Fix from $1,6002025-05-14 MEDIUM 6.5 CVE-2024-52601 iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have rea… Itop 2.7.12 / 3.1.3+ Fix from $1,6002025-05-14 MEDIUM 5.3 CVE-2025-3769 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver… Mitigation only Fix from $1,6002025-05-14 MEDIUM 5.3 CVE-2024-8988 The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 vi… Mitigation only Fix from $1,6002025-05-14 CRITICAL 9.8 CVE-2025-3605EPSS 7% The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and… Mitigation only Fix from $2,3002025-05-09 CRITICAL 9.8 CVE-2025-3810 The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due… Wpbookit 1.0.3+ Fix from $2,3002025-05-09 CRITICAL 9.8 CVE-2025-3811 The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due… Wpbookit 1.0.3+ Fix from $2,3002025-05-09 MEDIUM 6.5 CVE-2025-3853 The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 2.0.0 to 2.6.0 via the callback_generate… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.3 CVE-2025-3281 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Obj… Mitigation only Fix from $1,6002025-05-06 HIGH 8.8 CVE-2025-3610 The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This … Mitigation only Fix from $1,9502025-05-06 HIGH 7.3 CVE-2025-4210 A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers… Patch available Fix from $1,9502025-05-02 MEDIUM 6.5 CVE-2025-3874 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3… Wordpress Simple Paypal Shopping Cart 5.1.4+ Fix from $1,6002025-05-01