Total
2053 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-55231 | 1 Phpgurukul | 1 Online Notes Sharing Management System | 2026-06-17 | N/A | 4.3 MEDIUM |
| An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts due to missing authorization checks. This flaw exposes sensitive data and enables attackers to alter another user's information. | |||||
| CVE-2024-55186 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in the request URL. By changing the notification ID, an attacker can view sensitive mail details belonging to other users. | |||||
| CVE-2024-53617 | 2026-06-17 | N/A | 4.8 MEDIUM | ||
| A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML file on behalf of the admin user using IDOR in file upload. | |||||
| CVE-2024-53406 | 1 Espressif | 1 Esp-idf | 2026-06-17 | N/A | 8.8 HIGH |
| Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to execute security bypass attacks. | |||||
| CVE-2024-52601 | 1 Combodo | 1 Itop | 2026-06-17 | N/A | 6.5 MEDIUM |
| iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have read access to objects they're not allowed to see by querying an unprotected route. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue. | |||||
| CVE-2024-52511 | 1 Nextcloud | 1 Tables | 2026-06-17 | N/A | 6.3 MEDIUM |
| Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0. | |||||
| CVE-2024-52507 | 1 Nextcloud | 1 Tables | 2026-06-17 | N/A | 3.5 LOW |
| Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1. | |||||
| CVE-2024-52313 | 1 Amazon | 1 Data.all | 2026-06-17 | N/A | 4.3 MEDIUM |
| An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all. | |||||
| CVE-2024-52294 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR) vulnerability in the update_subscription endpoint allows any authenticated user to manipulate other users' Stripe subscriptions by simply modifying the email parameter in the request. The vulnerability exists in the subscription endpoint at `/api/subscription`. The endpoint uses an email parameter as a direct reference to user subscriptions without verifying object ownership. While authentication is required, there is no authorization check to verify if the authenticated user owns the referenced subscription. The issue was fixed in version 1.29.10. Support for arbitrarily presenting an email for update has been deprecated. | |||||
| CVE-2024-51559 | 1 63moons | 2 Aero, Wave 2.0 | 2026-06-17 | N/A | 6.5 MEDIUM |
| This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts. | |||||
| CVE-2024-50693 | 1 Sungrowpower | 1 Isolarcloud | 2026-06-17 | N/A | 9.1 CRITICAL |
| SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model. | |||||
| CVE-2024-50689 | 1 Sungrowpower | 1 Isolarcloud | 2026-06-17 | N/A | 9.1 CRITICAL |
| SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model. | |||||
| CVE-2024-50687 | 1 Sungrowpower | 1 Isolarcloud | 2026-06-17 | N/A | 9.1 CRITICAL |
| SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the devService API model. | |||||
| CVE-2024-50686 | 1 Sungrowpower | 1 Isolarcloud | 2026-06-17 | N/A | 9.1 CRITICAL |
| SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model. | |||||
| CVE-2024-50685 | 1 Sungrowpower | 1 Isolarcloud | 2026-06-17 | N/A | 9.1 CRITICAL |
| SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) via the powerStationService API model. | |||||
| CVE-2024-50651 | 1 Geeeeeeeek | 1 Java Shop | 2026-06-17 | N/A | 6.5 MEDIUM |
| java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter. | |||||
| CVE-2024-50483 | 1 Tareqhasan | 1 Meetup | 2026-06-17 | N/A | 9.8 CRITICAL |
| Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1. | |||||
| CVE-2024-50395 | 1 Qnap | 1 Media Streaming Add-on | 2026-06-17 | N/A | 8.8 HIGH |
| An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 2024/08/02 ) and later | |||||
| CVE-2024-4886 | 1 Buddyboss | 1 Buddyboss Platform | 2026-06-17 | N/A | 4.3 MEDIUM |
| The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request | |||||
| CVE-2024-4874 | 1 Bricksbuilder | 1 Bricks | 2026-06-17 | N/A | 4.3 MEDIUM |
| The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.8 via the postId parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to modify posts and pages created by other users including admins. As a requirement for this, an admin would have to enable access to the editor specifically for such a user or enable it for all users with a certain user account type. | |||||
