Vulnerability index

Browse CVEs

1,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.3 CVE-2025-3889 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3… Wordpress Simple Paypal Shopping Cart 5.1.4+ Fix from $1,6002025-05-01 HIGH 7.5 CVE-2025-4119 A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the file /queryTotal of the compon… Mall Mitigation only Fix from $1,9502025-04-30 HIGH 7.1 CVE-2025-3625 A security vulnerability was discovered in Moodle that can allow hackers to gain access to sensitive information about students and prevent them from… Moodle 4.3.12 / 4.4.8+ Fix from $1,9502025-04-25 HIGH 8.0 CVE-2025-25777 Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the … Bus Ticket Booking System No fix yet Fix from $1,9502025-04-24 CRITICAL 9.3 CVE-2025-42605 This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for the initiation, modification,… Mitigation only Fix from $2,3002025-04-23 HIGH 7.0 CVE-2025-3519 An authorization bypass in Unblu Spark allows a participant of a conversation to replace an existing, uploaded file. Every uploaded file in Unblu ge… Mitigation only Fix from $1,9502025-04-22 MEDIUM 5.3 CVE-2025-31147 Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 HIGH 7.5 CVE-2025-31360 Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users. Cloud Portal after 3.6.0 Fix from $1,9502025-04-15 MEDIUM 5.3 CVE-2025-31654 An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms"). Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-31945 An unauthenticated attacker can obtain other users' charger information. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-31950 An unauthenticated attacker can obtain EV charger energy consumption information of other users. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-30257 Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-27719 Unauthenticated attackers can query an API endpoint and get device details. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-27927 An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-27929 Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-27575 An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-27561 Unauthenticated attackers can rename "rooms" of arbitrary users. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-27565 An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-26857 Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers). Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-24315 Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users). Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-24850 An attacker can export other users' plant information. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 6.5 CVE-2025-25276 An unauthenticated attacker can hijack other users' devices and potentially control them. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-31933 An unauthenticated attacker can check the existence of usernames in the system by querying an API. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-31941 An unauthenticated attacker can obtain a list of smart devices by knowing a valid username. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-31949 An authenticated attacker can obtain any plant name by knowing the plant ID. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-31357 An unauthenticated attacker can obtain a user's plant list by knowing the username. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-30514 Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes"). Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-30254 An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-27568 An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response to this unsolicited request. Cloud Portal after 3.6.0 Fix from $1,6002025-04-15 MEDIUM 5.3 CVE-2025-27938 Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms"). Cloud Portal after 3.6.0 Fix from $1,6002025-04-15