Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-11284
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due…
Jobcareer
after 7.1
CRITICAL 9.8
CVE-2024-11285
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due…
Jobcareer
after 7.1
HIGH 8.8
CVE-2024-53406
Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the s…
Esp Idf
No fix yet
HIGH 7.7
CVE-2025-2271
A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insec…
Mitigation only
MEDIUM 5.3
CVE-2024-13887
The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …
Mitigation only
MEDIUM 6.5
CVE-2025-0337
ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability,…
Mitigation only
HIGH 7.6
CVE-2024-11216
Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik On…
Mitigation only
CRITICAL 9.0
CVE-2025-27507
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains In…
Zitadel
2.63.8 / 2.64.5+
HIGH 7.5
CVE-2024-8261
Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Securit…
Student Affairs Information System
24.0927+
MEDIUM 5.3
CVE-2024-10925
A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to …
GitLab
17.7.6 / 17.8.4+
MEDIUM 6.5
CVE-2025-25952
An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student In…
Academia Student Information System
Mitigation only
CRITICAL 9.1
CVE-2024-50685
SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService AP…
Isolarcloud
2024-10-31+
CRITICAL 9.1
CVE-2024-50686
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model.
Isolarcloud
2024-10-31+
CRITICAL 9.1
CVE-2024-50687
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService API model.
Isolarcloud
2024-10-31+
CRITICAL 9.1
CVE-2024-50689
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model.
Isolarcloud
2024-10-31+
CRITICAL 9.1
CVE-2024-50693
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.
Isolarcloud
2024-10-31+
HIGH 7.2
CVE-2025-26977
Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Contro…
Filebird
6.4.6+
MEDIUM 5.3
CVE-2025-26965
Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access …
Mitigation only
HIGH 8.1
CVE-2025-25282
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Ins…
Ragflow
0.14.1+
HIGH 7.5
CVE-2025-0352
Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing …
Mitigation only
MEDIUM 5.3
CVE-2024-13719
The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via …
Peprodev Ultimate Invoice
after 2.0.8
HIGH 8.4
CVE-2025-26788
StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
Mitigation only
MEDIUM 5.4
CVE-2024-13692
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vul…
Return Refund And Exchange For Woocommerce
4.4.6+
HIGH 7.1
CVE-2025-1270
Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by …
H6web
Mitigation only
HIGH 8.8
CVE-2024-34520
An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authe…
Mitigation only
MEDIUM 6.6
CVE-2025-24976
Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with…
Patch available
HIGH 7.5
CVE-2024-39033
In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII t…
Mitigation only
MEDIUM 5.3
CVE-2024-13372
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Refer…
Wp Job Portal
2.2.7+
MEDIUM 5.3
CVE-2024-13428
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Refer…
Wp Job Portal
2.2.7+
HIGH 7.5
CVE-2024-13694
The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direc…
Woocommerce Wishlist
1.8.8+