Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
GLPI incorrectly authorizes access to documents
TestLink 1.19 - Arbitrary File Download (Unauthenticated)
Chainlit versions prior to 2
Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
Affected devices do not properly enforce user authentication on specific API endpoints
Multiple vulnerabilities in Viafirma products
Spectrum broken authorization scheme
WooCommerce Square <= 5.1.1 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in get_token_by_id
Spree API has Unauthenticated IDOR - Guest Address
Improper authorization vulnerability exists in RICOH Streamline NX 3
Spree API has Authenticated Insecure Direct Object Reference (IDOR) via Order Modification
OPEXUS eComplaint IDOR
OPEXUS eCasePortal unauthenticated IDOR
WordPress Image Slider Slideshow plugin <= 1.8 - Insecure Direct Object References (IDOR) vulnerability
Information disclosure via IDOR in Asseco AMDX
WordPress Woffice Core plugin <= 5.4.30 - Insecure Direct Object References (IDOR) vulnerability
Optional Email <= 1.3.11 - Unauthenticated Privilege Escalation to Account Takeover
ACF to REST API <= 3.3.4 - Insecure Direct Object Reference to Authenticated (Contributor+) ACF Field/Option Modification
LearnPress – WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion
Sony BRAVIA Digital Signage 1.7.8 Client-Side Protection Bypass via IDOR
Showing 1 - 20 of 1,000+ results