
CVE-2025-53640
Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.
api-security-testinginformation-gatheringosint+3
1

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

ChilliCream Nitro GraphQL version 28.0.13 is vulnerable to multiple Stored Cross Site Scripting (XSS) Vulnerabilities




he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR