Vulnerabilities (CVE)

Filtered by CWE-639
Total 2053 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-34437 1 Wwbn 1 Avideo 2026-06-17 N/A 8.8 HIGH
AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects.
CVE-2025-34436 1 Wwbn 1 Avideo 2026-06-17 N/A 8.8 HIGH
AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks.
CVE-2025-34435 1 Wwbn 1 Avideo 2026-06-17 N/A 6.5 MEDIUM
AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the targeted video.
CVE-2025-34293 2026-06-17 N/A N/A
GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to the API's object endpoints allow an authenticated user to request arbitrary user IDs and receive sensitive account data for those users, including the stored password and the account's security question and answer. The exposed recovery data and encrypted password may be used to reset or take over the target account.
CVE-2025-34140 2026-06-17 N/A N/A
An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resources. The root cause was a misconfiguration in API authorization logic, which has since been corrected in SE.2025.1 and 2025.1.2.
CVE-2025-32373 1 Dnnsoftware 1 Dotnetnuke 2026-06-17 N/A 6.5 MEDIUM
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is fixed in 9.13.8.
CVE-2025-32223 2026-06-17 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4.
CVE-2025-31997 1 Hcltech 1 Unica Centralized Offer Management 2026-06-17 N/A 4.2 MEDIUM
HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files.
CVE-2025-31950 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An unauthenticated attacker can obtain EV charger energy consumption information of other users.
CVE-2025-31949 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An authenticated attacker can obtain any plant name by knowing the plant ID.
CVE-2025-31945 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An unauthenticated attacker can obtain other users' charger information.
CVE-2025-31941 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.
CVE-2025-31933 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
CVE-2025-31867 1 Joomsky 1 Js Job Manager 2026-06-17 N/A 5.4 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager js-jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through <= 2.0.2.
CVE-2025-31833 2026-06-17 N/A 4.9 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a through <= 1.2.8.
CVE-2025-31654 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").
CVE-2025-31360 1 Growatt 1 Cloud Portal 2026-06-17 N/A 6.5 MEDIUM
Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.
CVE-2025-31357 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
An unauthenticated attacker can obtain a user's plant list by knowing the username.
CVE-2025-31147 1 Growatt 1 Cloud Portal 2026-06-17 N/A 5.3 MEDIUM
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
CVE-2025-30777 2026-06-17 N/A 4.3 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a through <= 1.4.11.