Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Acf To Rest Api HIGH 7.5
CVE-2020-13700EPSS 13%

An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manip…

Fix: after 3.1.0
Fix from $1,950 2020-06-24
Xenapp MEDIUM 5.3
CVE-2020-13998

Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA er…

Mitigation only
Fix from $1,600 2020-06-11
Nextcloud Server HIGH 7.7
CVE-2020-8154

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a…

Fix: 17.0.5 / 18.0.3+
Fix from $1,950 2020-05-12
Oklok MEDIUM 6.5
CVE-2020-8791

The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticate…

No fix yet
Fix from $1,600 2020-05-04
Rundeck MEDIUM 6.5
CVE-2020-11009

In Rundeck before version 3.2.6, authenticated users can craft a request that reveals Execution data and logs and Job details that they are not autho…

Fix: 3.2.6+
Fix from $1,600 2020-04-29
Ca Api Developer Portal CRITICAL 9.8
CVE-2020-11658

CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.

Fix: after 4.3.1
Fix from $2,300 2020-04-15
Roc Partner Settlement HIGH 8.8
CVE-2020-9384

An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement 10.5 allows remote authentica…

No fix yet
Fix from $1,950 2020-04-14
Cipace HIGH 7.5
CVE-2020-11589

An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET reques…

Fix: 9.1+
Fix from $1,950 2020-04-06
Totemomail MEDIUM 5.4
CVE-2020-7918

An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of…

Mitigation only
Fix from $1,600 2020-03-27
Dradis MEDIUM 6.5
CVE-2019-19946

The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project team.

No fix yet
Fix from $1,600 2020-03-16
Grandit MEDIUM 6.5
CVE-2020-5539

GRANDIT Ver.1.6, Ver.2.0, Ver.2.1, Ver.2.2, Ver.2.3, and Ver.3.0 do not properly manage sessions, which allows remote attackers to impersonate an arb…

Mitigation only
Fix from $1,600 2020-03-02
Unify Openscape Uc Web Client HIGH 7.5
CVE-2019-19866

Atos Unify OpenScape UC Web Client V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows remote attackers to obtain sensitive informa…

Mitigation only
Fix from $1,950 2020-02-21
Asset Suite HIGH 7.1
CVE-2019-18998

Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables…

Fix: 9.4.2.6 / 9.5.3.2+
Fix from $1,950 2020-02-17
Secure File Transfer MEDIUM 6.5
CVE-2020-8503

Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by an authen…

Fix: after 6.0.1003
Fix from $1,600 2020-01-31
GitLab MEDIUM 5.3
CVE-2019-15581

An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or mai…

Fix: 12.1.12 / 12.2.6+
Fix from $1,600 2020-01-28
GitLab MEDIUM 5.3
CVE-2019-15582

An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer t…

Fix: 12.1.12 / 12.2.6+
Fix from $1,600 2020-01-28
Ftp Server MEDIUM 5.4
CVE-2020-5194

The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricte…

No fix yet
Fix from $1,600 2020-01-14
Citybook HIGH 7.5
CVE-2019-20209

The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR…

Fix: 1.0.6 / 1.2.2+
Fix from $1,950 2020-01-13
Ultimate Member MEDIUM 5.3
CVE-2020-6859

Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress …

Fix: after 2.1.2
Fix from $1,600 2020-01-13
Dgnwg03lm Firmware CRITICAL 9.8
CVE-2019-15913

An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communic…

No fix yet
Fix from $2,300 2019-12-20
GitLab MEDIUM 6.5
CVE-2019-5469

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users fil…

Fix: 11.11.6 / 12.0.4+
Fix from $1,600 2019-12-18
Znid 2426a Firmware HIGH 8.8
CVE-2014-8356EPSS 6%

The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modi…

No fix yet
Fix from $1,950 2019-11-21
Google Compute Engine MEDIUM 5.9
CVE-2019-16546

Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-th…

Fix: 4.2.0+
Fix from $1,600 2019-11-21
2.00\(abbx.3\) MEDIUM 6.5
CVE-2019-15815

ZyXEL P-1302-T10D v3 devices with firmware version 2.00(ABBX.3) and earlier do not properly enforce access control and could allow an unauthorized us…

Patch available
Fix from $1,600 2019-11-12
Eyecms HIGH 8.8
CVE-2019-17605

A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiti…

Fix: after 2019-10-15
Fix from $1,950 2019-11-07
Magento MEDIUM 6.5
CVE-2019-8235

An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2.1 prior to 2.1.17 versions. …

Fix: 2.1.17 / 2.2.8+
Fix from $1,600 2019-10-30
Popup Maker CRITICAL 9.1
CVE-2019-17574EPSS 9%

An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the…

Fix: 1.8.13+
Fix from $2,300 2019-10-14
Zabbix CRITICAL 9.1
CVE-2019-17382EPSS 54%

An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the…

Fix: after 4.4
Fix from $2,300 2019-10-09
Voyager HIGH 7.2
CVE-2019-17050

An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arb…

Fix: after 1.2.7
Fix from $1,950 2019-09-30
Bagisto HIGH 8.8
CVE-2019-16403

In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be mani…

Fix: 0.1.5+
Fix from $1,950 2019-09-18