Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Online Discussion Forum Site HIGH 7.5
CVE-2022-31295

An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.

No fix yet
Fix from $1,950 2022-06-16
Oauthenticator MEDIUM 6.5
CVE-2022-31027

OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets u…

Fix: 15.0.0+
Fix from $1,600 2022-06-09
Fedora CRITICAL 9.1
CVE-2022-1996

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

Fix: 2.16.0 / 3.8.0+
Fix from $2,300 2022-06-08
389 Directory Server HIGH 7.5
CVE-2022-1949

An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progr…

Fix: after 2.0.0
Fix from $1,950 2022-06-02
Automotive Shop Management System CRITICAL 9.8
CVE-2022-30495

In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change…

No fix yet
Fix from $2,300 2022-05-26
Spiffy Calendar MEDIUM 5.4
CVE-2022-29434

Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete e…

Fix: after 4.9.0
Fix from $1,600 2022-05-20
Winhotel.mx MEDIUM 5.3
CVE-2022-27247

onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth…

No fix yet
Fix from $1,600 2022-05-13
GitLab MEDIUM 5.3
CVE-2022-1352

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and …

Fix: 14.8.6 / 14.9.4+
Fix from $1,600 2022-05-11
Bus Pass Management System MEDIUM 6.5
CVE-2022-29008

An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensit…

No fix yet
Fix from $1,600 2022-05-11
2 Factor Authentication HIGH 7.5
CVE-2022-28986

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which…

No fix yet
Fix from $1,950 2022-05-10
Shopizer MEDIUM 6.5
CVE-2022-23061

In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) v…

Fix: after 2.17.0
Fix from $1,600 2022-05-01
Openemr MEDIUM 6.5
CVE-2022-1461

Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.

Fix: 6.1.0.1+
Fix from $1,600 2022-04-25
Openemr HIGH 8.3
CVE-2022-1459

Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.

Fix: 6.1.0.1+
Fix from $1,950 2022-04-25
Odyssey Portal HIGH 7.5
CVE-2022-26665

An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sens…

Fix: 17.1.20+
Fix from $1,950 2022-04-18
Paragon Active Assurance Control Center HIGH 7.5
CVE-2022-22190

An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to levera…

Mitigation only
Fix from $1,950 2022-04-14
Sunny Tripower Firmware HIGH 8.1
CVE-2021-46416

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie …

No fix yet
Fix from $1,950 2022-04-07
Blackhole For Bad Bots CRITICAL 9.1
CVE-2022-1165

The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests…

Fix: 3.3.2+
Fix from $2,300 2022-04-04
Partner Engagement Manager HIGH 7.1
CVE-2022-22331

IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details cause…

Patch available
Fix from $1,950 2022-04-01
Archer MEDIUM 6.5
CVE-2021-38362

In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecur…

Fix: 6.9.3.0.1+
Fix from $1,600 2022-03-30
Wowonder MEDIUM 5.3
CVE-2022-26254

WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to …

No fix yet
Fix from $1,600 2022-03-27
Crucible HIGH 7.5
CVE-2021-43957

Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vuln…

Fix: 4.8.9+
Fix from $1,950 2022-03-16
Openemr HIGH 8.1
CVE-2022-25471

An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas v…

Mitigation only
Fix from $1,950 2022-03-03
Rundeck MEDIUM 5.4
CVE-2021-41111

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticate…

Fix: 3.3.15 / 3.4.5+
Fix from $1,600 2022-02-28
Copy9 HIGH 7.5
CVE-2022-0732

The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating …

Mitigation only
Fix from $1,950 2022-02-24
Dolibarr Erp\/crm MEDIUM 6.5
CVE-2022-0731

Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

Fix: 16.0.0+
Fix from $1,600 2022-02-23
Url Parse CRITICAL 9.8
CVE-2022-0691

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

Fix: 1.5.9+
Fix from $2,300 2022-02-21
Url Parse CRITICAL 9.1
CVE-2022-0686

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

Fix: 1.5.8+
Fix from $2,300 2022-02-20
Varnishcache MEDIUM 5.3
CVE-2022-24979

An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does no…

Fix: 2.0.1+
Fix from $1,600 2022-02-19
Ez Platform Kernel MEDIUM 5.3
CVE-2022-25336

Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image…

Fix: 1.3.12 / 7.5.26+
Fix from $1,600 2022-02-18
Url Parse MEDIUM 5.3
CVE-2022-0639

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.

Fix: 1.5.7+
Fix from $1,600 2022-02-17