Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
OpenRemote Manager - Cross-Tenant IDOR in Bulk Alarm Deletion
Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings
Filament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fields
IDOR in Jira plugin subscription edit endpoint
Broken access control in MISP core allows cross-organization unauthorized modification or deletion of analyst data, event reports, collections, tem...
MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields
Craft CMS - Authorization Bypass in assets/preview-file Endpoint
Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/logs
Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
Path traversal in getPlaylist/deletePlaylist bypasses ownership check: any authenticated user can read or delete any other user's playlist
U.S. GAO EPDS and CBCA EDS user information disclosure
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter
PressPrimer Quiz <= 2.3.0 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Modification via 'quiz_id', 'item_id', and 'rule_...
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Ord...
TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint
Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint
Showing 1 - 20 of 1,000+ results