Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Easytor CRITICAL 9.8
CVE-2023-31182

EasyTor Applications – Authorization Bypass - EasyTor Applications may allow authorization bypass via unspecified method.

No fix yet
Fix from $2,300 2023-05-08
Newbee Mall MEDIUM 5.4
CVE-2023-30216

Insecure permissions in the updateUserInfo function of newbee-mall before commit 1f2c2dfy allows attackers to obtain user account information.

Fix: 2022-10-27+
Fix from $1,600 2023-05-04
Nginx Api Connectivity Manager HIGH 8.1
CVE-2023-28656

NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: So…

Fix: 1.3.0 / 1.5.0+
Fix from $1,950 2023-05-03
Ruby Help Desk MEDIUM 6.5
CVE-2023-1125

The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an a…

Fix: 1.3.4+
Fix from $1,600 2023-05-02
Alf HIGH 8.8
CVE-2023-2260

Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

Fix: 2.0-m4-2304+
Fix from $1,950 2023-04-24
Emui MEDIUM 6.5
CVE-2022-48313

The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may…

No fix yet
Fix from $1,600 2023-04-16
GitLab HIGH 7.5
CVE-2018-17449

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers co…

Fix: 11.1.7 / 11.2.4+
Fix from $1,950 2023-04-15
GitLab HIGH 7.5
CVE-2018-17455

An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive …

Fix: 11.1.7 / 11.2.4+
Fix from $1,950 2023-04-15
Vdesk MEDIUM 6.5
CVE-2022-45175

An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/…

Fix: after 018
Fix from $1,600 2023-04-14
Bhima MEDIUM 6.5
CVE-2023-0967

Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that sh…

No fix yet
Fix from $1,600 2023-04-05
Nxal 100 Firmware MEDIUM 6.5
CVE-2023-1749

The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could se…

Mitigation only
Fix from $1,600 2023-04-04
Nxal 100 Firmware HIGH 7.1
CVE-2023-1750

The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could re…

Mitigation only
Fix from $1,950 2023-04-04
Peppermint HIGH 8.1
CVE-2023-26984

An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted re…

No fix yet
Fix from $1,950 2023-03-29
Oaklouds Mailsherlock MEDIUM 5.3
CVE-2023-24842

HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial …

Mitigation only
Fix from $1,600 2023-03-27
Tronclass Ilearn MEDIUM 6.5
CVE-2023-24834

WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this…

Fix: 1.52.29198+
Fix from $1,600 2023-03-27
Faveo Servicedesk MEDIUM 6.5
CVE-2023-24625

Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.

No fix yet
Fix from $1,600 2023-03-24
Fedora HIGH 7.1
CVE-2023-28686

Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attac…

Fix: 0.2.3 / 0.3.2+
Fix from $1,950 2023-03-24
Digikent HIGH 8.8
CVE-2023-1462

Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Authentication Bypass, Authentic…

Fix: 23.03.20+
Fix from $1,950 2023-03-21
Woocommerce Multiple Customer Addresses \& Shipping HIGH 8.8
CVE-2023-0865

The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete an…

Fix: 21.7+
Fix from $1,950 2023-03-20
Teampass MEDIUM 5.4
CVE-2023-1463

Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

Fix: 3.0.0.23+
Fix from $1,600 2023-03-17
Play With Docker MEDIUM 6.5
CVE-2023-28109

Play With Docker is a browser-based Docker playground. Versions 0.0.2 and prior are vulnerable to domain hijacking. Because CORS configuration was no…

Patch available
Fix from $1,600 2023-03-16
Moodle MEDIUM 5.3
CVE-2021-36400

In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.

Fix: 3.9.8 / 3.10.5+
Fix from $1,600 2023-03-06
Yf Exam HIGH 7.5
CVE-2023-25403

CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format cha…

No fix yet
Fix from $1,950 2023-03-03
Single Connect HIGH 8.8
CVE-2023-0882

Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abu…

Fix: 2.16.1+
Fix from $1,950 2023-02-17
Mail MEDIUM 5.3
CVE-2023-25160

Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access th…

Fix: 1.11.8 / 1.12.9+
Fix from $1,600 2023-02-13
Baby Camera Firmware HIGH 7.5
CVE-2022-34138

Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive informati…

Mitigation only
Fix from $1,950 2023-02-03
Contentstudio CRITICAL 9.8
CVE-2023-0558

The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in v…

Fix: 1.2.6+
Fix from $2,300 2023-01-27
Quick Restaurant Menu HIGH 8.1
CVE-2023-0550

The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due…

Fix: 2.1.0+
Fix from $1,950 2023-01-27
Canvas Learning Management Service MEDIUM 6.5
CVE-2021-36539

Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL…

Fix: 2022-10-15+
Fix from $1,600 2023-01-26
Opentext Extended Ecm HIGH 8.8
CVE-2022-45927

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication …

Fix: 22.4+
Fix from $1,950 2023-01-18