Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Friendica CRITICAL 9.8
CVE-2024-27730

Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the…

Patch available
Fix from $2,300 2024-08-15
Unclassified MEDIUM 5.7
CVE-2024-21981

Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in…

Mitigation only
Fix from $1,600 2024-08-13
Unclassified MEDIUM 6.5
CVE-2024-39642

Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality Not Properly Constrained by ACL…

Mitigation only
Fix from $1,600 2024-08-13
Projectsend MEDIUM 5.3
CVE-2024-7658

A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the f…

Patch available
Fix from $1,600 2024-08-12
GitLab HIGH 8.1
CVE-2024-3035

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 1…

Fix: 17.0.6 / 17.1.4+
Fix from $1,950 2024-08-08
Arcsight Intelligence HIGH 8.8
CVE-2024-6357

Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.

Fix: 6.4.13+
Fix from $1,950 2024-08-06
Litestream MEDIUM 5.3
CVE-2024-41254

An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attacke…

Fix: after 0.3.13
Fix from $1,600 2024-07-31
Academy Lms HIGH 8.8
CVE-2024-38701

Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.

Fix: 2.0.5+
Fix from $1,950 2024-07-22
Streampark MEDIUM 6.5
CVE-2024-34457

On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone'…

Fix: 2.1.4+
Fix from $1,600 2024-07-22
Givewp MEDIUM 5.4
CVE-2024-5977

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a…

Fix: 3.14.0+
Fix from $1,600 2024-07-19
Unclassified CRITICAL 9.6
CVE-2024-5619

Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Con…

Mitigation only
Fix from $2,300 2024-07-18
Advisor Network HIGH 8.1
CVE-2024-38447

NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbit…

No fix yet
Fix from $1,950 2024-07-17
Advisor Network MEDIUM 6.5
CVE-2024-38446

NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of tha…

No fix yet
Fix from $1,600 2024-07-17
Observability MEDIUM 5.4
CVE-2024-39900

OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin …

Fix: 2.14+
Fix from $1,600 2024-07-09
Observability MEDIUM 5.4
CVE-2024-39901

OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugin…

Fix: 2.14+
Fix from $1,600 2024-07-09
Easyappointments MEDIUM 6.5
CVE-2023-3286

A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in una…

Fix: 1.5.0+
Fix from $1,600 2024-07-09
Easyappointments HIGH 8.8
CVE-2023-3287

A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege e…

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments HIGH 8.8
CVE-2023-3288

A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege …

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments MEDIUM 6.5
CVE-2023-3289

A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in…

Fix: 1.5.0+
Fix from $1,600 2024-07-09
Easyappointments MEDIUM 5.0
CVE-2023-3290

A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauth…

Fix: 1.5.0+
Fix from $1,600 2024-07-09
Easyappointments HIGH 8.1
CVE-2023-38055

A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (incl…

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments HIGH 8.1
CVE-2023-38050

A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (includi…

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments HIGH 8.1
CVE-2023-38051

A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (se…

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments HIGH 8.1
CVE-2023-38052

A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). Th…

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments HIGH 8.1
CVE-2023-38053

A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (in…

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments HIGH 8.1
CVE-2023-38054

A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (custo…

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments HIGH 8.1
CVE-2023-38047

A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (i…

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments HIGH 8.1
CVE-2023-38048

A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider)…

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Easyappointments HIGH 8.1
CVE-2023-38049

A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any …

Fix: 1.5.0+
Fix from $1,950 2024-07-09
Unclassified HIGH 7.7
CVE-2023-3285

A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This r…

Mitigation only
Fix from $1,950 2024-07-09