Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified HIGH 8.8
CVE-2024-48217

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

Mitigation only
Fix from $1,950 2024-11-01
Paid Memberships Pro CRITICAL 9.8
CVE-2024-37277

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACL…

Fix: 3.0.5+
Fix from $2,300 2024-11-01
Lr350 Firmware CRITICAL 9.1
CVE-2024-10654

A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functiona…

No fix yet
Fix from $2,300 2024-11-01
Beauty Parlour Management System HIGH 7.5
CVE-2024-51066

An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unaut…

No fix yet
Fix from $1,950 2024-10-31
Forminator Forms MEDIUM 5.3
CVE-2024-9700

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…

Fix: 1.36.1+
Fix from $1,600 2024-10-31
Lunary MEDIUM 6.5
CVE-2024-7473

An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability all…

Patch available
Fix from $1,600 2024-10-29
Lunary HIGH 8.1
CVE-2024-7474

In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by ma…

Fix: 1.3.4+
Fix from $1,950 2024-10-29
Meetup CRITICAL 9.8
CVE-2024-50483

Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: fr…

Fix: after 0.1
Fix from $2,300 2024-10-28
Ehrd Ctms HIGH 7.5
CVE-2024-10439

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specifi…

Fix: 10.8+
Fix from $1,950 2024-10-28
Wpschoolpress HIGH 8.8
CVE-2024-9637

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, a…

Fix: 2.2.11+
Fix from $1,950 2024-10-26
Radar CRITICAL 9.8
CVE-2024-10121

A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Inter…

Fix: after 1.0.8
Fix from $2,300 2024-10-18
Unclassified CRITICAL 9.8
CVE-2024-9263

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privileg…

Mitigation only
Fix from $2,300 2024-10-17
Otp Verification With Firebase CRITICAL 9.8
CVE-2024-9862

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, …

Fix: 3.6.1+
Fix from $2,300 2024-10-17
Unclassified HIGH 8.8
CVE-2024-9215

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct O…

Mitigation only
Fix from $1,950 2024-10-17
Unclassified MEDIUM 5.9
CVE-2023-32189

Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys

Mitigation only
Fix from $1,600 2024-10-16
Unclassified HIGH 7.7
CVE-2024-8040

An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated…

Mitigation only
Fix from $1,950 2024-10-16
Unclassified MEDIUM 6.5
CVE-2023-7286

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes …

Mitigation only
Fix from $1,600 2024-10-16
Cyber Protect CRITICAL 9.1
CVE-2024-49388

Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) befo…

Fix: after 15
Fix from $2,300 2024-10-15
Wp 2fa With Telegram HIGH 8.8
CVE-2024-9687

The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficie…

Fix: 3.1+
Fix from $1,950 2024-10-15
Junos Os Evolved MEDIUM 6.7
CVE-2024-47495

An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of t…

Fix: 21.2+
Fix from $1,600 2024-10-11
Open Webui MEDIUM 6.5
CVE-2024-7041

An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint…

No fix yet
Fix from $1,600 2024-10-09
Salon Booking System HIGH 8.8
CVE-2024-47316

Authorization Bypass Through User-Controlled Key vulnerability in Dimitri Grassi Salon booking system salon-booking-system.This issue affects Salon b…

Fix: 10.9.1+
Fix from $1,950 2024-10-05
Net Back Office MEDIUM 6.5
CVE-2024-47657

This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker co…

Fix: 5.5.002+
Fix from $1,600 2024-10-04
Meraki Mx65 Firmware MEDIUM 5.3
CVE-2024-20513

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthentic…

Fix: 18.211.2+
Fix from $1,600 2024-10-02
Unclassified MEDIUM 6.8
CVE-2021-37577

Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 th…

Mitigation only
Fix from $1,600 2024-10-01
Aimeos Frontend Controller MEDIUM 5.3
CVE-2024-39319

aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 20…

Fix: 2020.10.15 / 2021.10.8+
Fix from $1,600 2024-09-26
Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible HIGH 8.8
CVE-2024-8290

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direc…

Fix: 6.7.13+
Fix from $1,950 2024-09-25
Rest Api To Miniprogram CRITICAL 9.8
CVE-2024-8485

The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.…

Fix: after 4.7.1
Fix from $2,300 2024-09-25
Charitable CRITICAL 9.8
CVE-2024-8791

The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation i…

Fix: 1.8.1.15+
Fix from $2,300 2024-09-24
Envoy MEDIUM 6.5
CVE-2024-45806

Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy hea…

Fix: 1.28.7 / 1.29.9+
Fix from $1,600 2024-09-20