Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Extreme Xds MEDIUM 6.5
CVE-2024-4341

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by U…

Fix: 3928+
Fix from $1,600 2024-07-08
Traefik HIGH 7.5
CVE-2024-39321

Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allo…

Fix: 2.11.6 / 3.0.4+
Fix from $1,950 2024-07-05
Unclassified CRITICAL 9.8
CVE-2024-39223

An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to …

Mitigation only
Fix from $2,300 2024-07-03
Infosphere Information Server MEDIUM 5.4
CVE-2024-31898

IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using in…

Mitigation only
Fix from $1,600 2024-06-30
Page And Post Clone MEDIUM 5.4
CVE-2024-5942

The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'con…

Fix: 6.1+
Fix from $1,600 2024-06-29
Travel Apps CRITICAL 9.8
CVE-2024-1107

Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Contr…

Fix: 17.0.68+
Fix from $2,300 2024-06-27
Unclassified MEDIUM 6.5
CVE-2023-49112

Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing only its name via the "applicat…

Mitigation only
Fix from $1,600 2024-06-20
Myfinances MEDIUM 6.5
CVE-2024-37889

MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method …

Fix: 0.4.6+
Fix from $1,600 2024-06-14
Bl W1210m Firmware MEDIUM 6.3
CVE-2024-33373

An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authenti…

Mitigation only
Fix from $1,600 2024-06-14
Latepoint CRITICAL 9.1
CVE-2024-2472

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on …

Fix: 4.9.91+
Fix from $2,300 2024-06-14
Lunary MEDIUM 6.5
CVE-2024-5131

An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability a…

Fix: 1.2.25+
Fix from $1,600 2024-06-06
Lunary HIGH 8.8
CVE-2024-5128

An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulne…

Fix: 1.2.25+
Fix from $1,950 2024-06-06
Lunary HIGH 7.5
CVE-2024-5130

An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete …

Fix: 1.2.8+
Fix from $1,950 2024-06-06
Kanboard MEDIUM 6.3
CVE-2024-36399

Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php functio…

Fix: 1.2.37+
Fix from $1,600 2024-06-06
Buddyboss MEDIUM 5.3
CVE-2024-4750

The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID …

Fix: 2.6.0+
Fix from $1,600 2024-06-04
Mattermost Server MEDIUM 5.9
CVE-2024-32045

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linki…

Fix: 8.1.13 / 9.5.4+
Fix from $1,600 2024-05-26
Looker MEDIUM 6.5
CVE-2024-5166

An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML mode…

Mitigation only
Fix from $1,600 2024-05-22
Lunary MEDIUM 6.5
CVE-2024-4154

In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to…

Fix: 1.2.26+
Fix from $1,600 2024-05-21
Lunary HIGH 8.1
CVE-2024-4151

An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to…

Fix: 1.2.25+
Fix from $1,950 2024-05-20
Tutor Lms MEDIUM 6.5
CVE-2024-4279

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Delet…

Fix: 2.7.1+
Fix from $1,600 2024-05-16
Fortivoice HIGH 7.1
CVE-2023-40720

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allo…

Fix: after 6.4.8
Fix from $1,950 2024-05-14
Online Laundry Management System HIGH 8.8
CVE-2024-4819

A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function o…

No fix yet
Fix from $1,950 2024-05-14
Online Laundry Management System HIGH 8.8
CVE-2024-4817

A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code …

No fix yet
Fix from $1,950 2024-05-14
Unclassified HIGH 7.5
CVE-2024-33818

Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.

Mitigation only
Fix from $1,950 2024-05-14
Unclassified HIGH 7.5
CVE-2024-4538

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain a user's event ticket…

Mitigation only
Fix from $1,950 2024-05-07
Unclassified HIGH 7.5
CVE-2024-4537

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of a…

Mitigation only
Fix from $1,950 2024-05-07
Unclassified MEDIUM 5.3
CVE-2024-34383

Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n/a through 7.7…

Mitigation only
Fix from $1,600 2024-05-06
Filebird MEDIUM 5.4
CVE-2024-2346

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Fix: 5.6.4+
Fix from $1,600 2024-05-02
Unclassified HIGH 7.5
CVE-2024-24312

SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/UserMod…

Mitigation only
Fix from $1,950 2024-05-01
Novel Plus HIGH 7.5
CVE-2024-33383

Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request u…

Fix: after 4.3.0
Fix from $1,950 2024-04-30