Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Cacti HIGH 7.5
CVE-2023-37543

Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php.…

Fix: 1.2.6+
Fix from $1,950 2023-08-10
Ats Pro CRITICAL 9.8
CVE-2023-2958

Authorization Bypass Through User-Controlled Key vulnerability in Origin Software ATS Pro allows Authentication Abuse, Authentication Bypass. This i…

Fix: 20230714+
Fix from $2,300 2023-07-17
GitLab MEDIUM 6.5
CVE-2023-2190

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.…

Fix: 15.11.10 / 16.0.6+
Fix from $1,600 2023-07-13
Learndash HIGH 8.8
CVE-2023-3105

The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the…

Fix: after 4.6.0
Fix from $1,950 2023-07-12
Foundry Comments MEDIUM 5.3
CVE-2023-30956

A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if th…

Fix: 2.267.0+
Fix from $1,600 2023-07-10
Eventon MEDIUM 5.3
CVE-2023-3219EPSS 8%

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, all…

Fix: 2.1.2+
Fix from $1,600 2023-07-10
Emui CRITICAL 9.8
CVE-2023-37242

Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-vol…

Mitigation only
Fix from $2,300 2023-07-06
Solusvm HIGH 8.8
CVE-2022-42175

Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker to change the password and hostname of other custom…

Mitigation only
Fix from $1,950 2023-07-05
Sp Project \& Document Manager HIGH 8.8
CVE-2023-3063

The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. Thi…

Fix: after 4.67
Fix from $1,950 2023-06-30
macOS MEDIUM 5.5
CVE-2022-48505

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the …

Fix: 13.0+
Fix from $1,600 2023-06-28
Ipados MEDIUM 5.5
CVE-2023-32352

A logic issue was addressed with improved checks. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6…

Fix: 9.5 / 11.7.7+
Fix from $1,600 2023-06-23
Jshelpdesk HIGH 8.8
CVE-2023-23679

Authorization Bypass Through User-Controlled Key vulnerability in JS Help Desk js-support-ticket allows Accessing Functionality Not Properly Constrai…

Fix: after 2.7.7
Fix from $1,950 2023-06-23
Open Xchange Appsuite Backend MEDIUM 6.5
CVE-2023-26428

Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other use…

Fix: 7.10.6 / 8.11.0+
Fix from $1,600 2023-06-20
Android HIGH 7.8
CVE-2023-21131

In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitigations due to a logic error i…

Patch available
Fix from $1,950 2023-06-15
Stripe Payment Gateway HIGH 7.5
CVE-2023-34000

Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.

Fix: 7.4.1+
Fix from $1,950 2023-06-14
Lockcell Firmware CRITICAL 9.8
CVE-2023-3048

Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass. This issue affect…

Fix: 15.0+
Fix from $2,300 2023-06-13
Directorist MEDIUM 6.5
CVE-2023-1889

The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to imp…

Fix: after 7.5.4
Fix from $1,600 2023-06-09
Metform Elementor Contact Form Builder MEDIUM 6.5
CVE-2023-0688

The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, a…

Fix: after 3.3.1
Fix from $1,600 2023-06-09
Seeddms HIGH 8.8
CVE-2021-33223

An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file.

No fix yet
Fix from $1,950 2023-06-07
Mbconnect24 HIGH 8.8
CVE-2023-0985

An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2…

Fix: after 2.13.3
Fix from $1,950 2023-06-06
Kanboard MEDIUM 6.5
CVE-2023-33956

Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to an Insecure direc…

Fix: 1.2.30+
Fix from $1,600 2023-06-05
Amxgt 100 HIGH 8.1
CVE-2023-3066

Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including admi…

Fix: after 1.3.20
Fix from $1,950 2023-06-05
Dataease HIGH 8.1
CVE-2023-32310

DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulner…

Fix: 1.18.7+
Fix from $1,950 2023-06-01
Shop Beat Media Player CRITICAL 9.1
CVE-2022-36247

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.

Fix: 3.2.57+
Fix from $2,300 2023-05-30
Cbot Core HIGH 8.8
CVE-2023-2883

Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass. This issue affect…

Fix: 4.0.3.4 / 4.0.3.7+
Fix from $1,950 2023-05-25
Cargo Tracking System HIGH 8.8
CVE-2023-2065

Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication…

Fix: 3558f28+
Fix from $1,950 2023-05-24
Competition Management System HIGH 8.8
CVE-2023-2702

Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authentication Abuse, Authenticati…

Fix: 23.07+
Fix from $1,950 2023-05-23
Rental Module CRITICAL 9.8
CVE-2023-2713

Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows…

Fix: 23.05.15+
Fix from $2,300 2023-05-20
Wcfm Membership CRITICAL 9.8
CVE-2023-2276

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in …

Fix: after 2.10.7
Fix from $2,300 2023-05-20
Registrationmagic HIGH 7.2
CVE-2023-2548

The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due …

Fix: after 5.2.0.5
Fix from $1,950 2023-05-16