Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Customer Portal HIGH 7.5
CVE-2023-45893

An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to…

Mitigation only
Fix from $1,950 2024-01-02
Woopayments HIGH 7.5
CVE-2023-51503

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This …

Fix: 6.7.0+
Fix from $1,950 2023-12-31
Enterprise Server MEDIUM 5.3
CVE-2023-46646

Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check r…

Fix: 3.7.19 / 3.8.12+
Fix from $1,600 2023-12-21
Rate My Post MEDIUM 6.5
CVE-2023-49765

Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating…

Fix: 3.4.2+
Fix from $1,600 2023-12-21
Youzify MEDIUM 6.5
CVE-2023-47191

Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership…

Fix: 1.2.3+
Fix from $1,600 2023-12-21
Woocommerce Bookings HIGH 7.5
CVE-2023-32747

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a …

Fix: after 1.15.78
Fix from $1,950 2023-12-21
Shipping Multiple Addresses MEDIUM 6.5
CVE-2023-32799

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addres…

Fix: after 3.8.3
Fix from $1,600 2023-12-21
Woocommerce Subscriptions HIGH 7.5
CVE-2023-35914

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a throug…

Fix: 5.1.3+
Fix from $1,950 2023-12-20
Woopayments HIGH 7.5
CVE-2023-35916

Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This …

Fix: 5.9.1+
Fix from $1,950 2023-12-20
Woocommerce Square HIGH 8.1
CVE-2023-35876

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a thro…

Fix: 3.8.2+
Fix from $1,950 2023-12-20
Editorial Calendar HIGH 8.1
CVE-2023-36520

Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a th…

Fix: 3.8.0+
Fix from $1,950 2023-12-20
Sunshine Photo Cart MEDIUM 6.5
CVE-2023-41796

Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue…

Fix: 3.0+
Fix from $1,600 2023-12-20
Wpdiscuz MEDIUM 6.5
CVE-2023-46311

Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a …

Fix: 7.6.4+
Fix from $1,600 2023-12-20
Woocommerce Gocardless HIGH 7.5
CVE-2023-37871

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.

Fix: 2.5.7+
Fix from $1,950 2023-12-20
Photo Engine MEDIUM 5.4
CVE-2023-38513

Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engi…

Fix: 6.2.6+
Fix from $1,600 2023-12-20
Etl3100 Firmware CRITICAL 9.8
CVE-2023-6929

EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur when the application provides direct access…

Mitigation only
Fix from $2,300 2023-12-19
Stream MEDIUM 6.5
CVE-2022-43450

Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.

Fix: after 3.9.2
Fix from $1,600 2023-12-19
Wp Photo Album Plus HIGH 7.5
CVE-2023-49812

Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album…

Fix: after 8.5.02.005
Fix from $1,950 2023-12-19
Mattermost Server MEDIUM 5.3
CVE-2023-46701

Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allow…

Fix: after 9.2.1
Fix from $1,600 2023-12-12
Archer HIGH 8.8
CVE-2023-48641

Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a …

Fix: 6.13.0.3 / 6.14.0.1.2+
Fix from $1,950 2023-12-12
Cms360 MEDIUM 5.3
CVE-2023-6341

Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other…

Mitigation only
Fix from $1,600 2023-11-30
Openzfs HIGH 7.5
CVE-2023-49298

OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can r…

Fix: after 2.1.13
Fix from $1,950 2023-11-24
Sysaid MEDIUM 6.5
CVE-2023-33706

SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp o…

Fix: 23.2.15 / 23.2.50+
Fix from $1,600 2023-11-24
Headwind Mdm MEDIUM 5.4
CVE-2023-47316

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls…

No fix yet
Fix from $1,600 2023-11-22
Opensis HIGH 7.5
CVE-2023-38884

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote att…

Mitigation only
Fix from $1,950 2023-11-20
Emsigner MEDIUM 6.5
CVE-2023-43900

Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive dat…

No fix yet
Fix from $1,600 2023-11-14
Asyncssh MEDIUM 6.8
CVE-2023-46446

An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulati…

Fix: 2.14.1+
Fix from $1,600 2023-11-14
Moodle MEDIUM 5.4
CVE-2023-5544

Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Order Duplicator HIGH 8.8
CVE-2023-45380

In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can…

Fix: 1.1.8+
Fix from $1,950 2023-11-07
Tronclass Ilearn MEDIUM 6.5
CVE-2023-41356

NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can expl…

Mitigation only
Fix from $1,600 2023-11-03