Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Fedora MEDIUM 6.5
CVE-2022-0613

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

Fix: 1.19.8+
Fix from $1,600 2022-02-16
Scratchoauth2 MEDIUM 6.5
CVE-2021-46249

An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd4…

Fix: 2021-04-12+
Fix from $1,600 2022-02-15
Url Parse MEDIUM 5.3
CVE-2022-0512

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.

Fix: 1.5.6+
Fix from $1,600 2022-02-14
Chatwoot MEDIUM 6.5
CVE-2021-3813

Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.

Fix: after 2.1.1
Fix from $1,600 2022-02-09
Country Blocker MEDIUM 6.5
CVE-2021-25096

The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL

Fix: 2.26.5+
Fix from $1,600 2022-02-07
Tessa CRITICAL 9.8
CVE-2022-22832EPSS 14%

An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.

No fix yet
Fix from $2,300 2022-02-06
Selectsurvey.net HIGH 7.5
CVE-2021-41608

A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attac…

Fix: 5.052.000+
Fix from $1,950 2022-01-28
Synaman HIGH 7.5
CVE-2022-22828

An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via…

Fix: 5.0+
Fix from $1,950 2022-01-27
Enterprise Identity Cloud MEDIUM 5.3
CVE-2022-23856

An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as f…

No fix yet
Fix from $1,600 2022-01-24
Live Helper Chat MEDIUM 6.6
CVE-2022-0266

Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.

Fix: 3.92+
Fix from $1,600 2022-01-19
Designjet T920 Cr355a Firmware HIGH 7.5
CVE-2021-3965EPSS 5%

Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews.

Mitigation only
Fix from $1,950 2022-01-14
Growi HIGH 7.5
CVE-2021-3852

growi is vulnerable to Authorization Bypass Through User-Controlled Key

Fix: after 4.4.7
Fix from $1,950 2022-01-12
Tlr 2005ksh Firmware CRITICAL 9.8
CVE-2021-45428EPSS 57%

TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including H…

No fix yet
Fix from $2,300 2022-01-03
Carinal Tien Hospital Health Report System HIGH 7.3
CVE-2021-44160

Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege b…

Mitigation only
Fix from $1,950 2021-12-29
Online Enrollment Management System MEDIUM 6.5
CVE-2021-40579

https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected by: Incorrect Access Control. …

No fix yet
Fix from $1,600 2021-12-28
Logo Carousel HIGH 8.1
CVE-2021-24739

The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by …

Fix: 3.4.2+
Fix from $1,950 2021-12-21
Patrowlmanager HIGH 7.5
CVE-2021-43828

PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) h…

Fix: 1.7.7+
Fix from $1,950 2021-12-14
Seafile Server MEDIUM 5.9
CVE-2021-43820

Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve…

Fix: 8.0.8 / 8.0.15+
Fix from $1,600 2021-12-14
Glfusion CRITICAL 9.8
CVE-2021-44949

glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.

No fix yet
Fix from $2,300 2021-12-14
Elgg MEDIUM 5.9
CVE-2021-3964

elgg is vulnerable to Authorization Bypass Through User-Controlled Key

Fix: 3.3.22+
Fix from $1,600 2021-12-01
Kimai2 MEDIUM 6.5
CVE-2021-3992

kimai2 is vulnerable to Improper Access Control

Fix: 1.16.2+
Fix from $1,600 2021-12-01
Emc Streaming Data Platform MEDIUM 6.5
CVE-2021-36329

Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially expl…

Fix: 1.3+
Fix from $1,600 2021-11-30
Advanced Forms HIGH 8.8
CVE-2021-24892

Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrar…

Fix: 1.6.9+
Fix from $1,950 2021-11-23
Concrete Cms HIGH 7.5
CVE-2021-22951

Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concre…

Fix: 8.5.7+
Fix from $1,950 2021-11-19
Concrete Cms HIGH 7.5
CVE-2021-22967

In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Convers…

Fix: 8.5.7+
Fix from $1,950 2021-11-19
H8 Ssrms MEDIUM 6.5
CVE-2021-3380

Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print Invoice Func…

No fix yet
Fix from $1,600 2021-11-10
Squaretype MEDIUM 5.3
CVE-2021-24840

The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of…

Fix: 3.0.4+
Fix from $1,600 2021-11-08
Jira HIGH 7.5
CVE-2021-41305

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an …

Fix: 8.13.12+
Fix from $1,950 2021-10-26
Jira HIGH 7.5
CVE-2021-41306

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure …

Fix: 8.13.12 / 8.20.0+
Fix from $1,950 2021-10-26
Jira HIGH 7.5
CVE-2021-41307

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private f…

Fix: 8.13.12 / 8.20.0+
Fix from $1,950 2021-10-26