Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Lost And Found Information System CRITICAL 9.8
CVE-2023-38965

Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.

No fix yet
Fix from $2,300 2023-11-03
Minical HIGH 8.8
CVE-2023-46478

An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.

No fix yet
Fix from $1,950 2023-10-30
Wpdiscuz MEDIUM 5.3
CVE-2023-3869

The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment functi…

Fix: after 7.6.3
Fix from $1,600 2023-10-20
Wpdiscuz MEDIUM 5.3
CVE-2023-3998

The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in…

Fix: after 7.6.3
Fix from $1,600 2023-10-20
Tetra\ HIGH 8.1
CVE-2022-24401

Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TD…

Mitigation only
Fix from $1,950 2023-10-19
Tetra\ MEDIUM 5.9
CVE-2022-24400

A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.

Mitigation only
Fix from $1,600 2023-10-19
Inlong CRITICAL 9.8
CVE-2023-43668

Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some se…

Fix: after 1.8.0
Fix from $2,300 2023-10-16
Utime Master MEDIUM 6.5
CVE-2023-45393

An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information v…

No fix yet
Fix from $1,600 2023-10-13
Etg150 Firmware MEDIUM 6.5
CVE-2023-45396

An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter running on version 3.12.

Mitigation only
Fix from $1,600 2023-10-11
Zookeeper CRITICAL 9.1
CVE-2023-44981

Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru…

Fix: 3.7.2 / 3.8.3+
Fix from $2,300 2023-10-11
Fortianalyzer MEDIUM 6.5
CVE-2023-44249

An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer…

Fix: 7.2.4+
Fix from $1,600 2023-10-10
Wazuh Dashboard HIGH 8.8
CVE-2023-42455

Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API admin…

Fix: 4.4.2+
Fix from $1,950 2023-10-09
Epp Firmware MEDIUM 6.7
CVE-2023-26237

An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.

Fix: 8.00.22.0010+
Fix from $1,600 2023-10-05
Peix MEDIUM 6.5
CVE-2023-2544

Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an authenticated user could chan…

Mitigation only
Fix from $1,600 2023-10-03
Buddyboss MEDIUM 5.4
CVE-2023-32669

Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other…

Mitigation only
Fix from $1,600 2023-10-03
Qsige MEDIUM 6.5
CVE-2023-4099

The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions t…

Mitigation only
Fix from $1,600 2023-10-03
Qsige MEDIUM 6.5
CVE-2023-4101

The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. A…

Mitigation only
Fix from $1,600 2023-10-03
Aybs HIGH 8.8
CVE-2023-4934

Authorization Bypass Through User-Controlled Key vulnerability in Usta AYBS allows Authentication Abuse, Authentication Bypass. This issue affects A…

Fix: 1.0.3+
Fix from $1,950 2023-09-27
Cyber Protect MEDIUM 5.3
CVE-2023-44205

Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before…

Fix: 15+
Fix from $1,600 2023-09-27
Cyber Protect CRITICAL 9.1
CVE-2023-44206

Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux…

Fix: 15+
Fix from $2,300 2023-09-27
Cyber Protect HIGH 8.1
CVE-2023-44154

Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux…

Fix: 15+
Fix from $1,950 2023-09-27
Crew MEDIUM 6.5
CVE-2023-42334

An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user par…

No fix yet
Fix from $1,600 2023-09-20
Simplr Registration Form Plus\+ HIGH 8.8
CVE-2023-4213

The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.4.5. T…

Fix: after 2.4.5
Fix from $1,950 2023-09-13
S\/4 Hana MEDIUM 5.3
CVE-2023-41368

The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by …

Mitigation only
Fix from $1,600 2023-09-12
Searchblox HIGH 8.8
CVE-2020-10130

SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system.

Fix: 9.1+
Fix from $1,950 2023-09-06
Zem800 Firmware MEDIUM 5.5
CVE-2023-4587

An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered…

Mitigation only
Fix from $1,600 2023-09-04
Enterprise Linux MEDIUM 6.5
CVE-2023-38201

A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allo…

Patch available
Fix from $1,600 2023-08-25
Netmaker HIGH 7.5
CVE-2023-32078

Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions prior to 0.17.1 and 0.18.6 in …

Fix: 0.17.1+
Fix from $1,950 2023-08-24
Phplist MEDIUM 6.7
CVE-2023-27576

An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, al…

Patch available
Fix from $1,600 2023-08-18
Tigergraph HIGH 8.8
CVE-2023-28481

An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergra…

No fix yet
Fix from $1,950 2023-08-14