Total
2053 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-34437 | 1 Wwbn | 1 Avideo | 2026-06-17 | N/A | 8.8 HIGH |
| AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects. | |||||
| CVE-2025-34436 | 1 Wwbn | 1 Avideo | 2026-06-17 | N/A | 8.8 HIGH |
| AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks. | |||||
| CVE-2025-34435 | 1 Wwbn | 1 Avideo | 2026-06-17 | N/A | 6.5 MEDIUM |
| AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the targeted video. | |||||
| CVE-2025-34293 | 2026-06-17 | N/A | N/A | ||
| GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API. Authenticated requests to the API's object endpoints allow an authenticated user to request arbitrary user IDs and receive sensitive account data for those users, including the stored password and the account's security question and answer. The exposed recovery data and encrypted password may be used to reset or take over the target account. | |||||
| CVE-2025-34140 | 2026-06-17 | N/A | N/A | ||
| An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resources. The root cause was a misconfiguration in API authorization logic, which has since been corrected in SE.2025.1 and 2025.1.2. | |||||
| CVE-2025-32373 | 1 Dnnsoftware | 1 Dotnetnuke | 2026-06-17 | N/A | 6.5 MEDIUM |
| DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is fixed in 9.13.8. | |||||
| CVE-2025-32223 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.4. | |||||
| CVE-2025-31997 | 1 Hcltech | 1 Unica Centralized Offer Management | 2026-06-17 | N/A | 4.2 MEDIUM |
| HCL Unica Centralized Offer Management is vulnerable to Insecure Direct Object References (IDOR). An attacker can bypass authorization and access resources in the system directly, for example database records or files. | |||||
| CVE-2025-31950 | 1 Growatt | 1 Cloud Portal | 2026-06-17 | N/A | 5.3 MEDIUM |
| An unauthenticated attacker can obtain EV charger energy consumption information of other users. | |||||
| CVE-2025-31949 | 1 Growatt | 1 Cloud Portal | 2026-06-17 | N/A | 5.3 MEDIUM |
| An authenticated attacker can obtain any plant name by knowing the plant ID. | |||||
| CVE-2025-31945 | 1 Growatt | 1 Cloud Portal | 2026-06-17 | N/A | 5.3 MEDIUM |
| An unauthenticated attacker can obtain other users' charger information. | |||||
| CVE-2025-31941 | 1 Growatt | 1 Cloud Portal | 2026-06-17 | N/A | 5.3 MEDIUM |
| An unauthenticated attacker can obtain a list of smart devices by knowing a valid username. | |||||
| CVE-2025-31933 | 1 Growatt | 1 Cloud Portal | 2026-06-17 | N/A | 5.3 MEDIUM |
| An unauthenticated attacker can check the existence of usernames in the system by querying an API. | |||||
| CVE-2025-31867 | 1 Joomsky | 1 Js Job Manager | 2026-06-17 | N/A | 5.4 MEDIUM |
| Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager js-jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Job Manager: from n/a through <= 2.0.2. | |||||
| CVE-2025-31833 | 2026-06-17 | N/A | 4.9 MEDIUM | ||
| Authorization Bypass Through User-Controlled Key vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a through <= 1.2.8. | |||||
| CVE-2025-31654 | 1 Growatt | 1 Cloud Portal | 2026-06-17 | N/A | 5.3 MEDIUM |
| An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms"). | |||||
| CVE-2025-31360 | 1 Growatt | 1 Cloud Portal | 2026-06-17 | N/A | 6.5 MEDIUM |
| Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users. | |||||
| CVE-2025-31357 | 1 Growatt | 1 Cloud Portal | 2026-06-17 | N/A | 5.3 MEDIUM |
| An unauthenticated attacker can obtain a user's plant list by knowing the username. | |||||
| CVE-2025-31147 | 1 Growatt | 1 Cloud Portal | 2026-06-17 | N/A | 5.3 MEDIUM |
| Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users. | |||||
| CVE-2025-30777 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Authorization Bypass Through User-Controlled Key vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a through <= 1.4.11. | |||||
