Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2024-13457
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.…
Event Tickets
5.18.1.1+
MEDIUM 6.5
CVE-2025-22608
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing auth…
Coolify
4.0.0+
HIGH 8.8
CVE-2024-10497
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an
authorized attacker to modify values outside those…
Mitigation only
MEDIUM 6.3
CVE-2024-11146
TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect pu…
Truefiling
3.1.112.19+
MEDIUM 6.5
CVE-2025-0058
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request …
Sap Basis
Patch available
HIGH 8.1
CVE-2024-42169
HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user…
Dryice Myxalytics
Mitigation only
CRITICAL 9.8
CVE-2024-10215
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin …
Wpbookit
1.6.6+
MEDIUM 5.4
CVE-2024-44450
Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.
No fix yet
HIGH 8.8
CVE-2024-13040
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote…
Mitigation only
MEDIUM 5.3
CVE-2024-12103
The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, an…
Mitigation only
MEDIUM 6.5
CVE-2024-55471
Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to acc…
Patch available
HIGH 8.8
CVE-2024-55506
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obta…
Complaint Management System
No fix yet
HIGH 7.5
CVE-2024-4464
Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-33…
Media Server
1.4-2680 / 2.0.5-3152+
MEDIUM 6.5
CVE-2024-9819
Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.
This issue affects NG Analy…
Mitigation only
MEDIUM 5.3
CVE-2024-12309
The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and…
Mitigation only
MEDIUM 5.9
CVE-2024-12483
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the comp…
Ujcms
9.6.3+
HIGH 7.5
CVE-2024-42422
Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remo…
Networker
19.10.0.6 / 19.11.0.3+
HIGH 8.8
CVE-2024-50395
An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability…
Media Streaming Add On
500.1.1.6+
MEDIUM 6.5
CVE-2024-10671
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to…
Button Block
1.1.5+
HIGH 8.1
CVE-2024-10855
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of serv…
Sirv
7.3.1+
HIGH 7.5
CVE-2024-11318
An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a r…
Mitigation only
MEDIUM 6.5
CVE-2024-52511
Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could b…
Tables
0.8.0+
MEDIUM 6.5
CVE-2024-50651
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modify…
Java Shop
No fix yet
HIGH 7.3
CVE-2024-10174
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Inse…
Wp Project Manager
2.6.14+
HIGH 7.6
CVE-2021-27700
SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner mode can switch to another cus…
Mitigation only
HIGH 8.1
CVE-2023-47543
An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticat…
Fortiportal
7.0.4+
HIGH 8.1
CVE-2024-11073
A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /…
Hospital Management System
No fix yet
MEDIUM 6.5
CVE-2024-9262
The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…
Mitigation only
HIGH 7.5
CVE-2024-43438
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users…
Moodle
4.1.12 / 4.2.9+
MEDIUM 6.5
CVE-2024-51559
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could explo…
Aero
1.1.7 / 120820241550+