Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Unclassified CRITICAL 9.1
CVE-2019-19755

ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of al…

Mitigation only
Fix from $2,300 2024-04-30
Hospital Management System HIGH 7.6
CVE-2024-28320

Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthori…

No fix yet
Fix from $1,950 2024-04-29
Doctor Appointment Management System HIGH 8.8
CVE-2024-4294

A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is s…

No fix yet
Fix from $1,950 2024-04-27
Zammad CRITICAL 9.1
CVE-2024-33668

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker c…

Fix: 6.3.0+
Fix from $2,300 2024-04-26
Profilegrid HIGH 8.8
CVE-2024-32808

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

Fix: 5.8.0+
Fix from $1,950 2024-04-24
Rate My Post MEDIUM 5.3
CVE-2024-32823

Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rat…

Fix: 3.4.5+
Fix from $1,600 2024-04-24
Profilegrid HIGH 8.8
CVE-2024-32772

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

Fix: 5.8.0+
Fix from $1,950 2024-04-24
Webid HIGH 8.8
CVE-2024-32166

Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction …

No fix yet
Fix from $1,950 2024-04-19
Wp Ultimate Review HIGH 7.5
CVE-2024-32683

Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.…

Fix: 2.3.0+
Fix from $1,950 2024-04-19
Lunary HIGH 8.1
CVE-2024-1626

An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, within the project update endpoint…

Fix: 1.0.0+
Fix from $1,950 2024-04-16
Itop MEDIUM 5.4
CVE-2023-45808

iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In othe…

Fix: 2.7.10 / 3.0.4+
Fix from $1,600 2024-04-15
Unclassified MEDIUM 6.9
CVE-2024-22439

A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series products. This vulnerability could be exploited to ga…

No fix yet
Fix from $1,600 2024-04-15
Biotime MEDIUM 6.5
CVE-2023-51141

An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization compone…

No fix yet
Fix from $1,600 2024-04-11
Lunary MEDIUM 6.5
CVE-2024-1625

An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allowing unauthorized deletion of …

Patch available
Fix from $1,600 2024-04-10
Learnpress MEDIUM 5.4
CVE-2024-1289

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.…

Fix: 4.2.6.4+
Fix from $1,600 2024-04-09
Webos CRITICAL 9.8
CVE-2023-6317

A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without …

No fix yet
Fix from $2,300 2024-04-09
Savane HIGH 7.5
CVE-2024-27630

Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the t…

Fix: 3.13+
Fix from $1,950 2024-04-08
Ex200 Firmware CRITICAL 9.1
CVE-2024-31815

In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

No fix yet
Fix from $2,300 2024-04-08
Profilegrid HIGH 7.1
CVE-2024-31291

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.

Fix: 5.7.7+
Fix from $1,950 2024-04-07
Bookingpress MEDIUM 5.4
CVE-2024-31296

Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1…

Fix: 1.0.82+
Fix from $1,600 2024-04-07
Unclassified HIGH 8.8
CVE-2023-6523

Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse. This issue affects Extreme XD…

Mitigation only
Fix from $1,950 2024-04-05
Computer Laboratory Management System MEDIUM 5.4
CVE-2024-3139

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue…

No fix yet
Fix from $1,600 2024-04-01
Unclassified MEDIUM 6.5
CVE-2024-30543

Authorization Bypass Through User-Controlled Key vulnerability in UPQODE Whizz.This issue affects Whizzy: from n/a through 1.1.18.

Mitigation only
Fix from $1,600 2024-03-31
Unclassified MEDIUM 5.3
CVE-2024-31095

Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.…

No fix yet
Fix from $1,600 2024-03-31
Profilegrid MEDIUM 6.5
CVE-2024-30513

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.

Fix: 5.7.3+
Fix from $1,600 2024-03-29
Jumpserver MEDIUM 5.3
CVE-2024-29020

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive informa…

Fix: 3.10.6+
Fix from $1,600 2024-03-29
Jumpserver MEDIUM 5.3
CVE-2024-29024

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Dire…

Fix: 3.10.6+
Fix from $1,600 2024-03-29
Unclassified MEDIUM 6.5
CVE-2024-1313

It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE …

Mitigation only
Fix from $1,600 2024-03-26
Oneuptime HIGH 8.3
CVE-2024-29194

OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data wit…

Fix: 7.0.1815+
Fix from $1,950 2024-03-24
Control M MEDIUM 6.8
CVE-2024-1604

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and ma…

Fix: 9.0.20.238 / 9.0.21.201+
Fix from $1,600 2024-03-18