Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Employee Task Management System CRITICAL 9.8
CVE-2024-2577

A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown c…

Mitigation only
Fix from $2,300 2024-03-18
Employee Task Management System CRITICAL 9.8
CVE-2024-2574

A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this vulnerability is an unknown …

Mitigation only
Fix from $2,300 2024-03-18
Employee Task Management System CRITICAL 9.8
CVE-2024-2575

A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. Affected by this issue is so…

Mitigation only
Fix from $2,300 2024-03-18
Employee Task Management System CRITICAL 9.8
CVE-2024-2576

A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of t…

Mitigation only
Fix from $2,300 2024-03-18
Masmobile Asp.net Services MEDIUM 6.5
CVE-2023-36483

Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS v…

Fix: after 1.16.18
Fix from $1,600 2024-03-16
Bagisto MEDIUM 6.5
CVE-2023-36238

Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.

No fix yet
Fix from $1,600 2024-03-13
Contact Form Builder MEDIUM 5.3
CVE-2024-1640

The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to …

Fix: 2.10.2+
Fix from $1,600 2024-03-13
Feedwordpress MEDIUM 5.3
CVE-2024-0839

The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missi…

Fix: 2024.0428+
Fix from $1,600 2024-03-13
Go Zero CRITICAL 9.1
CVE-2024-27302

go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - which is an array of domains allo…

Fix: 1.4.4+
Fix from $2,300 2024-03-06
Client Login Extension HIGH 7.8
CVE-2024-1470

Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Cod…

Mitigation only
Fix from $1,950 2024-02-29
Moodle MEDIUM 5.3
CVE-2024-25983

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise ava…

Fix: 4.1.9 / 4.2.6+
Fix from $1,600 2024-02-19
Banner MEDIUM 6.5
CVE-2023-49339

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData e…

Fix: after 9.17
Fix from $1,600 2024-02-13
Mappress Maps For Wordpress MEDIUM 5.3
CVE-2024-0421

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a …

Fix: 2.88.16+
Fix from $1,600 2024-02-12
Hearing Tracking System HIGH 8.8
CVE-2023-6724

Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking…

Fix: 7.0+
Fix from $1,950 2024-02-09
Mia Med HIGH 8.8
CVE-2023-6515

Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abuse. This issue affects MİA-ME…

Fix: 1.0.7+
Fix from $1,950 2024-02-08
Terminal Handler MEDIUM 6.5
CVE-2023-47022

Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV …

Mitigation only
Fix from $1,600 2024-02-06
Minimal Coming Soon \& Maintenance Mode MEDIUM 5.3
CVE-2024-1075

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions u…

Fix: after 2.37
Fix from $1,600 2024-02-05
Kali Forms HIGH 8.1
CVE-2024-22305

Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This iss…

Fix: 2.3.37+
Fix from $1,950 2024-01-31
Relevanssi MEDIUM 5.3
CVE-2023-7199

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and pr…

Fix: after 2.25.0
Fix from $1,600 2024-01-29
Modernanet Hospital Management System 2024 HIGH 7.5
CVE-2024-23747

The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vuln…

No fix yet
Fix from $1,950 2024-01-29
Sinergia HIGH 7.5
CVE-2024-0580

Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extr…

Mitigation only
Fix from $1,950 2024-01-18
Qloapps MEDIUM 6.5
CVE-2023-36235

An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.

Fix: 1.6.0+
Fix from $1,600 2024-01-17
Wp Customer Area MEDIUM 6.5
CVE-2023-6824

The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to r…

Fix: 8.2.1+
Fix from $1,600 2024-01-16
Javascript CRITICAL 9.8
CVE-2024-22206

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth(…

Fix: 4.29.3+
Fix from $2,300 2024-01-12
Post Smtp CRITICAL 9.8
CVE-2023-6875EPSS 90%

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized …

Fix: after 2.8.7
Fix from $2,300 2024-01-11
Fortiportal MEDIUM 5.4
CVE-2023-48783EPSS 22%

An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, v…

Fix: 7.0.7 / 7.2.2+
Fix from $1,600 2024-01-10
Simatic Cn 4100 Firmware HIGH 8.8
CVE-2023-49251

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected applicatio…

Fix: 2.7+
Fix from $1,950 2024-01-09
Clinic Queuing System CRITICAL 9.8
CVE-2024-0264EPSS 18%

A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of t…

No fix yet
Fix from $2,300 2024-01-07
Woocommerce Stripe CRITICAL 9.8
CVE-2023-51502

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Strip…

Fix: after 7.6.1
Fix from $2,300 2024-01-05
Insight HIGH 7.5
CVE-2023-45892

An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive custome…

Mitigation only
Fix from $1,950 2024-01-02