Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.3 CVE-2024-13457 The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.… Event Tickets 5.18.1.1+ Fix from $1,6002025-01-30 MEDIUM 6.5 CVE-2025-22608 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing auth… Coolify 4.0.0+ Fix from $1,6002025-01-24 HIGH 8.8 CVE-2024-10497 CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those… Mitigation only Fix from $1,9502025-01-17 MEDIUM 6.3 CVE-2024-11146 TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect pu… Truefiling 3.1.112.19+ Fix from $1,6002025-01-17 MEDIUM 6.5 CVE-2025-0058 In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request … Sap Basis Patch available Fix from $1,6002025-01-14 HIGH 8.1 CVE-2024-42169 HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user… Dryice Myxalytics Mitigation only Fix from $1,9502025-01-11 CRITICAL 9.8 CVE-2024-10215 The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin … Wpbookit 1.6.6+ Fix from $2,3002025-01-09 MEDIUM 5.4 CVE-2024-44450 Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190. No fix yet Fix from $1,6002025-01-07 HIGH 8.8 CVE-2024-13040 The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote… Mitigation only Fix from $1,9502024-12-31 MEDIUM 5.3 CVE-2024-12103 The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, an… Mitigation only Fix from $1,6002024-12-24 MEDIUM 6.5 CVE-2024-55471 Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to acc… Patch available Fix from $1,6002024-12-20 HIGH 8.8 CVE-2024-55506 An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obta… Complaint Management System No fix yet Fix from $1,9502024-12-18 HIGH 7.5 CVE-2024-4464 Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-33… Media Server 1.4-2680 / 2.0.5-3152+ Fix from $1,9502024-12-18 MEDIUM 6.5 CVE-2024-9819 Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse. This issue affects NG Analy… Mitigation only Fix from $1,6002024-12-17 MEDIUM 5.3 CVE-2024-12309 The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and… Mitigation only Fix from $1,6002024-12-13 MEDIUM 5.9 CVE-2024-12483 A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the comp… Ujcms 9.6.3+ Fix from $1,6002024-12-12 HIGH 7.5 CVE-2024-42422 Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remo… Networker 19.10.0.6 / 19.11.0.3+ Fix from $1,9502024-12-03 HIGH 8.8 CVE-2024-50395 An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability… Media Streaming Add On 500.1.1.6+ Fix from $1,9502024-11-22 MEDIUM 6.5 CVE-2024-10671 The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to… Button Block 1.1.5+ Fix from $1,6002024-11-21 HIGH 8.1 CVE-2024-10855 The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of serv… Sirv 7.3.1+ Fix from $1,9502024-11-20 HIGH 7.5 CVE-2024-11318 An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a r… Mitigation only Fix from $1,9502024-11-18 MEDIUM 6.5 CVE-2024-52511 Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could b… Tables 0.8.0+ Fix from $1,6002024-11-15 MEDIUM 6.5 CVE-2024-50651 java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modify… Java Shop No fix yet Fix from $1,6002024-11-15 HIGH 7.3 CVE-2024-10174 The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Inse… Wp Project Manager 2.6.14+ Fix from $1,9502024-11-13 HIGH 7.6 CVE-2021-27700 SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner mode can switch to another cus… Mitigation only Fix from $1,9502024-11-12 HIGH 8.1 CVE-2023-47543 An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticat… Fortiportal 7.0.4+ Fix from $1,9502024-11-12 HIGH 8.1 CVE-2024-11073 A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /… Hospital Management System No fix yet Fix from $1,9502024-11-11 MEDIUM 6.5 CVE-2024-9262 The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version… Mitigation only Fix from $1,6002024-11-09 HIGH 7.5 CVE-2024-43438 A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users… Moodle 4.1.12 / 4.2.9+ Fix from $1,9502024-11-07 MEDIUM 6.5 CVE-2024-51559 This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could explo… Aero 1.1.7 / 120820241550+ Fix from $1,6002024-11-04