Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Vault CRITICAL 9.1
CVE-2022-40186

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deploymen…

Fix: 1.9.9 / 1.10.6+
Fix from $2,300 2022-09-22
Titan Anti Spam \& Security MEDIUM 5.3
CVE-2022-2877

The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowi…

Fix: 7.3.1+
Fix from $1,600 2022-09-16
Air 4920 Firmware CRITICAL 9.1
CVE-2022-38789

An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to arbitrary values, …

Fix: 2020-08-04+
Fix from $2,300 2022-09-15
Eigen\&wijzer Ouderapp HIGH 7.5
CVE-2022-36539

WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and chi…

Fix: 1.1.22+
Fix from $1,950 2022-09-07
Matrix MEDIUM 5.3
CVE-2022-32277

Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a re…

Mitigation only
Fix from $1,600 2022-09-06
Doctor\'s Appointment System CRITICAL 9.8
CVE-2022-36202

Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access…

Mitigation only
Fix from $2,300 2022-08-31
Sensei Lms MEDIUM 5.3
CVE-2022-2034

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to acce…

Fix: 4.5.0+
Fix from $1,600 2022-08-29
Tooljet HIGH 8.8
CVE-2022-3019

The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comme…

Fix: 1.23.0+
Fix from $1,950 2022-08-29
Candlepin MEDIUM 5.5
CVE-2021-4142

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (sim…

Fix: after 4.1.8-1
Fix from $1,600 2022-08-24
Tabit HIGH 7.5
CVE-2022-34770

Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive information such as health stateme…

Fix: 3.27.0+
Fix from $1,950 2022-08-22
Tabit HIGH 7.5
CVE-2022-34775

Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the rese…

Fix: 3.27.0+
Fix from $1,950 2022-08-22
Student Result Or Employee Database MEDIUM 5.4
CVE-2022-2312

The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in us…

Fix: 1.7.5+
Fix from $1,600 2022-08-22
Mealie MEDIUM 6.5
CVE-2022-34621

Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords …

Mitigation only
Fix from $1,600 2022-08-19
Openemr MEDIUM 5.4
CVE-2022-2824

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,600 2022-08-15
Searchwp Live Ajax Search MEDIUM 5.3
CVE-2022-2535

The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allo…

Fix: 1.6.2+
Fix from $1,600 2022-08-15
Openemr MEDIUM 6.5
CVE-2022-2730

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,600 2022-08-09
Wsm Downloader HIGH 7.5
CVE-2022-2367

The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to th…

Fix: after 1.4.0
Fix from $1,950 2022-08-08
Affiliate For Woocommerce MEDIUM 6.5
CVE-2022-36284

Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal …

Fix: after 4.7.0
Fix from $1,600 2022-08-05
Yop Poll MEDIUM 5.3
CVE-2022-1600

The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possib…

Fix: 6.4.3+
Fix from $1,600 2022-08-01
Mv720 Firmware MEDIUM 6.5
CVE-2022-33944

The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “De…

Mitigation only
Fix from $1,600 2022-07-20
Mv720 Firmware MEDIUM 5.4
CVE-2022-34150

The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device ID…

Mitigation only
Fix from $1,600 2022-07-20
Hypr Server HIGH 8.8
CVE-2022-2193

Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticato…

Fix: 6.14.1+
Fix from $1,950 2022-07-19
Wp User Manager HIGH 7.5
CVE-2021-24655

The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a r…

Fix: 2.6.3+
Fix from $1,950 2022-07-17
Octopus Server MEDIUM 5.3
CVE-2022-1881

In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project E…

Fix: 2021.3.13021 / 2022.1.2894+
Fix from $1,600 2022-07-15
Keycloak CRITICAL 9.8
CVE-2022-1245

A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…

Fix: 18.0.0+
Fix from $2,300 2022-07-08
Priority MEDIUM 6.3
CVE-2022-23173

this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - de…

Fix: 22.0+
Fix from $1,600 2022-07-06
Marval Msm HIGH 8.8
CVE-2022-31883

Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys i…

Mitigation only
Fix from $1,950 2022-06-28
Parse Path HIGH 7.3
CVE-2022-0624

Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.

Fix: 5.0.0+
Fix from $1,950 2022-06-28
Projectsend MEDIUM 5.7
CVE-2017-20101

A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_down…

No fix yet
Fix from $1,600 2022-06-27
Wp Email HIGH 7.5
CVE-2022-1614

The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possi…

Fix: 2.69.0+
Fix from $1,950 2022-06-20