Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Puma MEDIUM 5.4
CVE-2024-45614

Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwar…

Fix: 5.6.9 / 6.4.3+
Fix from $1,600 2024-09-19
Next.js HIGH 7.5
CVE-2024-46982EPSS 59%

Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non…

Fix: 13.5.7 / 14.2.10+
Fix from $1,950 2024-09-17
Powermail HIGH 7.5
CVE-2024-47047

An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting i…

Fix: after 12.4.0
Fix from $1,950 2024-09-17
Secure Authentication Server HIGH 7.5
CVE-2024-46937

An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SA…

Fix: 1.9.040924+
Fix from $1,950 2024-09-16
Woocommerce Multiple Free Gift MEDIUM 5.3
CVE-2022-3459

The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due t…

Fix: after 1.2.3
Fix from $1,600 2024-09-14
Lunary MEDIUM 6.5
CVE-2024-6087

An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an at…

Fix: 1.4.9+
Fix from $1,600 2024-09-13
Soliclub HIGH 7.5
CVE-2024-3305

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensiti…

Fix: 4.4.0 / 5.2.1+
Fix from $1,950 2024-09-12
Soliclub HIGH 7.5
CVE-2024-3306

Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control…

Fix: 4.4.0 / 5.2.1+
Fix from $1,950 2024-09-12
Soplanning CRITICAL 9.8
CVE-2024-27113

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view se…

Fix: 1.52.02+
Fix from $2,300 2024-09-11
Aim Star MEDIUM 6.5
CVE-2024-45786

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote atta…

Mitigation only
Fix from $1,600 2024-09-11
Fortianalyzer MEDIUM 6.5
CVE-2023-44254

An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version …

Fix: 7.2.5+
Fix from $1,600 2024-09-10
Unclassified CRITICAL 10.0
CVE-2024-45032

A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.…

Mitigation only
Fix from $2,300 2024-09-10
Back Office Software MEDIUM 6.5
CVE-2024-8601

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An auth…

Fix: 1.0.0+
Fix from $1,600 2024-09-09
Forumwp HIGH 8.8
CVE-2024-8428

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all …

Fix: after 2.0.2
Fix from $1,950 2024-09-06
Accord Ors HIGH 7.5
CVE-2024-1744

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive…

Fix: 7.3.2.1+
Fix from $1,950 2024-09-06
Wp Recall CRITICAL 9.8
CVE-2024-8292

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up…

Fix: 16.26.9+
Fix from $2,300 2024-09-06
Wp Extended MEDIUM 5.4
CVE-2024-8123

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and in…

Fix: 3.0.9+
Fix from $1,600 2024-09-04
Powermail MEDIUM 5.3
CVE-2024-45232

An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting…

Fix: 7.5.0 / 8.5.0+
Fix from $1,600 2024-08-29
Thingworx MEDIUM 6.5
CVE-2024-40395

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of acces…

Mitigation only
Fix from $1,600 2024-08-27
Zephyr Project Manager HIGH 7.1
CVE-2024-43916

Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from …

Fix: 3.3.103+
Fix from $1,950 2024-08-26
Lib9p MEDIUM 6.5
CVE-2024-8158

A bug in the 9p authentication implementation within lib9p allows an attacker with an existing valid user within the configured auth server to impers…

Fix: 2024-08-24+
Fix from $1,600 2024-08-25
User Private Files MEDIUM 6.5
CVE-2024-7848

The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Fix: 2.1.1+
Fix from $1,600 2024-08-22
Unclassified MEDIUM 5.3
CVE-2024-43350

Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6…

Mitigation only
Fix from $1,600 2024-08-18
Unclassified HIGH 7.5
CVE-2024-43315

Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Str…

Mitigation only
Fix from $1,950 2024-08-18
Zephyr Project Manager CRITICAL 9.8
CVE-2024-43322

Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from …

Fix: 3.3.101+
Fix from $2,300 2024-08-18
Wpforo Forum HIGH 8.1
CVE-2024-43288

Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.

Fix: 2.3.5+
Fix from $1,950 2024-08-18
Wp Job Portal HIGH 8.8
CVE-2024-43266

Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue affects WP Job Portal: from n/a …

Fix: 2.1.9+
Fix from $1,950 2024-08-18
Masteriyo HIGH 8.1
CVE-2024-43239

Authorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo -…

Fix: 1.11.5+
Fix from $1,950 2024-08-18
Upkeeper Manager MEDIUM 6.5
CVE-2024-42463

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the Sy…

Fix: 5.1.10+
Fix from $1,600 2024-08-16
Upkeeper Manager MEDIUM 6.5
CVE-2024-42464

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the Sy…

Fix: 5.1.10+
Fix from $1,600 2024-08-16