Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Listserv HIGH 7.5
CVE-2022-40319EPSS 7%

The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a w…

No fix yet
Fix from $1,950 2023-01-17
Memos MEDIUM 5.3
CVE-2022-4806

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-28
Memos MEDIUM 5.4
CVE-2022-4811

Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-28
Memos MEDIUM 6.5
CVE-2022-4812

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-28
Memos MEDIUM 5.3
CVE-2022-4798

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-28
Memos MEDIUM 6.5
CVE-2022-4799

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-28
Memos MEDIUM 5.4
CVE-2022-4802

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-28
Memos HIGH 8.8
CVE-2022-4803

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,950 2022-12-28
Liuos HIGH 7.8
CVE-2022-46179

LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to s…

Patch available
Fix from $1,950 2022-12-28
Memos CRITICAL 9.8
CVE-2022-4686

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.

Fix: 0.9.0+
Fix from $2,300 2022-12-23
Jeg Elementor Kit HIGH 7.5
CVE-2022-3805

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions …

Fix: 2.5.7+
Fix from $1,950 2022-12-22
Concourse MEDIUM 5.4
CVE-2022-31683

Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body inclu…

Fix: 6.7.9 / 7.8.3+
Fix from $1,600 2022-12-19
Passwordstate MEDIUM 6.5
CVE-2022-3876

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This …

No fix yet
Fix from $1,600 2022-12-19
All In One Security MEDIUM 5.3
CVE-2022-4097

The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (lik…

Fix: 5.0.8+
Fix from $1,600 2022-12-12
Vitrea View MEDIUM 6.5
CVE-2022-38765

Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized acce…

Fix: 7.8+
Fix from $1,600 2022-12-09
Prens Student Information System HIGH 8.8
CVE-2022-2808

Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping In…

Fix: 2.1.11+
Fix from $1,950 2022-12-02
Omnia Mpx Node Firmware HIGH 7.5
CVE-2022-43326

An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attacke…

Fix: 1.5.0+
Fix from $1,950 2022-11-29
Ourphoto HIGH 7.5
CVE-2022-24187

The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. O…

No fix yet
Fix from $1,950 2022-11-28
Appwash HIGH 8.1
CVE-2022-3589

An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker woul…

Mitigation only
Fix from $1,950 2022-11-21
Wpdiscuz HIGH 8.8
CVE-2022-43492

Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.

Mitigation only
Fix from $1,950 2022-11-18
Backclick MEDIUM 5.3
CVE-2022-44005

An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionali…

No fix yet
Fix from $1,600 2022-11-16
Quiz And Survey Master HIGH 8.8
CVE-2021-36906

Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.

Fix: after 7.3.6
Fix from $1,950 2022-11-03
Fortimail MEDIUM 6.5
CVE-2022-39945

An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may …

Fix: after 7.0.3
Fix from $1,600 2022-11-02
Hubshare HIGH 7.5
CVE-2022-39018

Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a know…

Fix: 3.3.11.3+
Fix from $1,950 2022-10-31
Spring Security CRITICAL 9.8
CVE-2022-31692

Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatc…

Fix: 5.6.9 / 5.7.5+
Fix from $2,300 2022-10-31
Orion Platform MEDIUM 5.4
CVE-2022-36966

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object re…

Fix: 2020.2.6+
Fix from $1,600 2022-10-20
Nopcommerce HIGH 7.5
CVE-2022-33077

An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.

Fix: after 4.50.2
Fix from $1,950 2022-10-19
Asp.net Web Forms Controls HIGH 7.5
CVE-2022-41479

The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /…

No fix yet
Fix from $1,950 2022-10-18
Octopus Server MEDIUM 6.5
CVE-2022-2828

In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR)…

Fix: after 2022.3.10586
Fix from $1,600 2022-10-13
Restricted Site Access MEDIUM 5.3
CVE-2022-1613

The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which m…

Fix: 7.3.2+
Fix from $1,600 2022-09-26