Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Deck HIGH 8.1
CVE-2021-39225

Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows ano…

Fix: 1.2.9 / 1.4.5+
Fix from $1,950 2021-10-25
Yellowfin MEDIUM 5.4
CVE-2021-36387

In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially craft…

Fix: 9.6.1+
Fix from $1,600 2021-10-14
Yellowfin HIGH 7.5
CVE-2021-36388

In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability e…

Fix: 9.6.1+
Fix from $1,950 2021-10-14
Yellowfin HIGH 7.5
CVE-2021-36389

In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploita…

Fix: 9.6.1+
Fix from $1,950 2021-10-14
R08sfcpu Firmware HIGH 7.5
CVE-2021-20599

Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/…

Mitigation only
Fix from $1,950 2021-10-14
Panel HIGH 8.1
CVE-2021-41129

Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati…

Fix: 1.6.2+
Fix from $1,950 2021-10-06
Paypal HIGH 7.5
CVE-2021-41120

sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was…

Fix: 1.2.4 / 1.3.1+
Fix from $1,950 2021-10-05
Booking Core MEDIUM 5.3
CVE-2021-37331

Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade Lic…

No fix yet
Fix from $1,600 2021-10-04
Gila Cms HIGH 7.5
CVE-2021-37777

Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just…

No fix yet
Fix from $1,950 2021-10-04
Infinias Access Control HIGH 8.8
CVE-2021-41847

An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials assigned to…

Fix: after 6.7.10708.0
Fix from $1,950 2021-10-01
Ecs Router Controller Ecs Firmware HIGH 8.8
CVE-2021-41298

ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on use…

Mitigation only
Fix from $1,950 2021-09-30
Ecs Router Controller Ecs Firmware CRITICAL 9.8
CVE-2021-41301

ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. T…

Mitigation only
Fix from $2,300 2021-09-30
Ulisting HIGH 8.8
CVE-2021-36874

Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).

Fix: after 2.0.5
Fix from $1,950 2021-09-27
Security Guardium MEDIUM 5.4
CVE-2021-29773

IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an i…

Patch available
Fix from $1,600 2021-09-15
Windows 10 MEDIUM 6.5
CVE-2021-38624

Windows Key Storage Provider Security Feature Bypass Vulnerability

Patch available
Fix from $1,600 2021-09-15
Teamcenter Visualization HIGH 8.8
CVE-2021-40355

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (Al…

Fix: 12.4.0.8 / 13.0.0.7+
Fix from $1,950 2021-09-14
Industrial Edge Management CRITICAL 9.8
CVE-2021-37184

A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker could change the the password of…

Fix: 1.3+
Fix from $2,300 2021-09-14
Richdocuments HIGH 7.5
CVE-2021-37628

Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares i…

Fix: 3.8.4 / 4.2.1+
Fix from $1,950 2021-09-07
Circles MEDIUM 6.5
CVE-2021-37630

Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed …

Fix: 0.19.5 / 0.20.11+
Fix from $1,600 2021-09-07
Deck MEDIUM 6.5
CVE-2021-37631

Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In aff…

Fix: 1.2.9 / 1.4.4+
Fix from $1,600 2021-09-07
Adobe Commerce HIGH 8.8
CVE-2021-36032

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil…

Fix: after 2.4.2
Fix from $1,950 2021-09-01
Openemr MEDIUM 6.5
CVE-2021-40352EPSS 10%

OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.

No fix yet
Fix from $1,600 2021-09-01
Cloud Foundation HIGH 7.2
CVE-2021-22023

The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to v…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Lifterlms HIGH 7.5
CVE-2021-24562

The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue…

Fix: 4.21.2+
Fix from $1,950 2021-08-23
Shopware MEDIUM 6.5
CVE-2021-37709

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log…

Fix: 6.4.3.1+
Fix from $1,600 2021-08-16
Flygo MEDIUM 5.4
CVE-2021-37212

The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote at…

Fix: 1.91.1+
Fix from $1,600 2021-08-09
Flygo HIGH 8.8
CVE-2021-37214

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, re…

Fix: 1.91.1+
Fix from $1,950 2021-08-09
Akaunting HIGH 8.1
CVE-2021-36801

Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed i…

Fix: after 2.1.12
Fix from $1,950 2021-08-04
User Profile Picture MEDIUM 5.4
CVE-2021-24473

The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default aut…

Fix: 2.6.0+
Fix from $1,600 2021-08-02
Online HIGH 7.5
CVE-2021-32744

Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gai…

Fix: 4.2.17-1 / 6.4.9-5+
Fix from $1,950 2021-07-21