Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
CRITICAL 9.8 CVE-2024-11284 The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due… Jobcareer after 7.1 Fix from $2,3002025-03-14 CRITICAL 9.8 CVE-2024-11285 The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due… Jobcareer after 7.1 Fix from $2,3002025-03-14 HIGH 8.8 CVE-2024-53406 Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the s… Esp Idf No fix yet Fix from $1,9502025-03-13 HIGH 7.7 CVE-2025-2271 A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insec… Mitigation only Fix from $1,9502025-03-13 MEDIUM 5.3 CVE-2024-13887 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all … Mitigation only Fix from $1,6002025-03-13 MEDIUM 6.5 CVE-2025-0337 ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability,… Mitigation only Fix from $1,6002025-03-06 HIGH 7.6 CVE-2024-11216 Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in PozitifIK Pik On… Mitigation only Fix from $1,9502025-03-05 CRITICAL 9.0 CVE-2025-27507 The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZITADEL's Admin API contains In… Zitadel 2.63.8 / 2.64.5+ Fix from $2,3002025-03-04 HIGH 7.5 CVE-2024-8261 Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Securit… Student Affairs Information System 24.0927+ Fix from $1,9502025-03-03 MEDIUM 5.3 CVE-2024-10925 A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to … GitLab 17.7.6 / 17.8.4+ Fix from $1,6002025-03-03 MEDIUM 6.5 CVE-2025-25952 An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student In… Academia Student Information System Mitigation only Fix from $1,6002025-03-03 CRITICAL 9.1 CVE-2024-50685 SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService AP… Isolarcloud 2024-10-31+ Fix from $2,3002025-02-26 CRITICAL 9.1 CVE-2024-50686 SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model. Isolarcloud 2024-10-31+ Fix from $2,3002025-02-26 CRITICAL 9.1 CVE-2024-50687 SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService API model. Isolarcloud 2024-10-31+ Fix from $2,3002025-02-26 CRITICAL 9.1 CVE-2024-50689 SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model. Isolarcloud 2024-10-31+ Fix from $2,3002025-02-26 CRITICAL 9.1 CVE-2024-50693 SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model. Isolarcloud 2024-10-31+ Fix from $2,3002025-02-26 HIGH 7.2 CVE-2025-26977 Authorization Bypass Through User-Controlled Key vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Contro… Filebird 6.4.6+ Fix from $1,9502025-02-25 MEDIUM 5.3 CVE-2025-26965 Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access … Mitigation only Fix from $1,6002025-02-25 HIGH 8.1 CVE-2025-25282 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Ins… Ragflow 0.14.1+ Fix from $1,9502025-02-21 HIGH 7.5 CVE-2025-0352 Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing … Mitigation only Fix from $1,9502025-02-20 MEDIUM 5.3 CVE-2024-13719 The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via … Peprodev Ultimate Invoice after 2.0.8 Fix from $1,6002025-02-19 HIGH 8.4 CVE-2025-26788 StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction. Mitigation only Fix from $1,9502025-02-14 MEDIUM 5.4 CVE-2024-13692 The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vul… Return Refund And Exchange For Woocommerce 4.4.6+ Fix from $1,6002025-02-14 HIGH 7.1 CVE-2025-1270 Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by … H6web Mitigation only Fix from $1,9502025-02-13 HIGH 8.8 CVE-2024-34520 An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authe… Mitigation only Fix from $1,9502025-02-12 MEDIUM 6.6 CVE-2025-24976 Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with… Patch available Fix from $1,6002025-02-11 HIGH 7.5 CVE-2024-39033 In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII t… Mitigation only Fix from $1,9502025-02-06 MEDIUM 5.3 CVE-2024-13372 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Refer… Wp Job Portal 2.2.7+ Fix from $1,6002025-02-01 MEDIUM 5.3 CVE-2024-13428 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Refer… Wp Job Portal 2.2.7+ Fix from $1,6002025-02-01 HIGH 7.5 CVE-2024-13694 The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direc… Woocommerce Wishlist 1.8.8+ Fix from $1,9502025-01-30