Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Jetpack MEDIUM 5.3
CVE-2021-24374

The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to com…

Fix: 9.8+
Fix from $1,600 2021-06-21
End To End Encryption MEDIUM 6.5
CVE-2021-22906

Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated user…

Fix: 1.5.3 / 1.6.3+
Fix from $1,600 2021-06-11
Windows 10 MEDIUM 5.5
CVE-2021-31970

Windows TCP/IP Driver Security Feature Bypass Vulnerability

Patch available
Fix from $1,600 2021-06-08
Nextcloud Server CRITICAL 9.1
CVE-2021-32654

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive …

Fix: 19.0.11 / 20.0.10+
Fix from $2,300 2021-06-01
Listeo MEDIUM 6.5
CVE-2021-24318

The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any …

Fix: 1.6.11+
Fix from $1,600 2021-06-01
Paxstore HIGH 8.1
CVE-2020-36126

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation. PAXSTOR…

Fix: after 7.0.8_20200511171508
Fix from $1,950 2021-05-07
Fuel Cms HIGH 8.8
CVE-2020-23722

An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id…

No fix yet
Fix from $1,950 2021-03-10
Glpi MEDIUM 6.5
CVE-2021-21324

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Fix: 9.5.4+
Fix from $1,600 2021-03-08
Glpi MEDIUM 5.7
CVE-2021-21255

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…

Patch available
Fix from $1,600 2021-03-02
Magento MEDIUM 5.3
CVE-2021-21022

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in …

Fix: 2.3.6+
Fix from $1,600 2021-02-11
Securetrack MEDIUM 5.7
CVE-2020-13462

Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.

Mitigation only
Fix from $1,600 2021-02-09
Op\'art Devis MEDIUM 5.3
CVE-2020-16194

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to an…

Fix: 4.0.2+
Fix from $1,600 2021-02-04
Favorites MEDIUM 5.3
CVE-2021-26024EPSS 19%

The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for an…

Fix: 1.0.2+
Fix from $1,600 2021-02-03
Newbee Mall HIGH 7.5
CVE-2020-23449

newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthor…

Patch available
Fix from $1,950 2021-01-26
Crucible MEDIUM 5.3
CVE-2020-29446

Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulner…

Fix: 4.8.5+
Fix from $1,600 2021-01-18
Magento Commerce MEDIUM 5.3
CVE-2021-21012

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR)…

Fix: after 2.3.6
Fix from $1,600 2021-01-13
Magento HIGH 8.1
CVE-2021-21013

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR)…

Fix: after 2.4.1
Fix from $1,950 2021-01-13
Mantisbt HIGH 7.5
CVE-2020-35849

An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view th…

Fix: 2.24.4+
Fix from $1,950 2020-12-30
Woocommerce MEDIUM 5.3
CVE-2020-29156

The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetc…

Fix: 4.7.0+
Fix from $1,600 2020-12-27
Business Workflow MEDIUM 6.5
CVE-2020-26175

In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile info…

Fix: 1.18.1+
Fix from $1,600 2020-12-18
Business Workflow MEDIUM 5.3
CVE-2020-26178

In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.

Fix: 1.18.1+
Fix from $1,600 2020-12-18
P1302 T10 V3 Firmware HIGH 7.5
CVE-2020-20183

Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privil…

Mitigation only
Fix from $1,950 2020-12-14
Roomos MEDIUM 6.5
CVE-2020-26068

A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to gene…

Fix: 9.10.3 / 9.12.4+
Fix from $1,600 2020-11-18
Webcit MEDIUM 6.5
CVE-2020-27742

An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails v…

Fix: after 926
Fix from $1,600 2020-10-28
Asset Performance Management Classic MEDIUM 5.3
CVE-2020-16240

GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in…

Fix: after 4.4
Fix from $1,600 2020-09-23
Workforce Optimization MEDIUM 5.3
CVE-2020-23446

Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API

No fix yet
Fix from $1,600 2020-09-22
1crm HIGH 8.6
CVE-2020-15958

An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to acce…

Fix: after 8.6.7
Fix from $1,950 2020-09-18
Cloudforms MEDIUM 6.5
CVE-2020-10779

Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege ch…

Mitigation only
Fix from $1,600 2020-08-11
Ofbiz MEDIUM 5.3
CVE-2020-13923EPSS 5%

IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04

Fix: 17.12.04+
Fix from $1,600 2020-07-15
Linkplay CRITICAL 9.8
CVE-2019-15310EPSS 8%

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could …

No fix yet
Fix from $2,300 2020-07-01