Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
GitLab HIGH 7.5
CVE-2019-15725

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure…

Fix: 12.0.8 / 12.1.8+
Fix from $1,950 2019-09-16
Webpanel HIGH 7.5
CVE-2019-14724

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an e-mail forwarding destination…

No fix yet
Fix from $1,950 2019-09-11
Webpanel MEDIUM 6.5
CVE-2019-14721

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a target user from phpMyAdmin …

No fix yet
Fix from $1,600 2019-09-10
Centos Web Panel MEDIUM 6.5
CVE-2019-14245

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) fr…

No fix yet
Fix from $1,600 2019-08-21
Centos Web Panel MEDIUM 6.5
CVE-2019-14246

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any…

No fix yet
Fix from $1,600 2019-08-21
Humatrix 7 HIGH 7.5
CVE-2019-14932

The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website vi…

No fix yet
Fix from $1,950 2019-08-12
Magento HIGH 7.5
CVE-2019-7950

An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthentica…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento HIGH 7.3
CVE-2019-7890

An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Magento MEDIUM 5.3
CVE-2019-7864

An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento …

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento MEDIUM 6.5
CVE-2019-7872

An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.…

Fix: 2.1.18 / 2.2.9+
Fix from $1,600 2019-08-02
Magento HIGH 7.5
CVE-2019-7854

An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can l…

Fix: 2.1.18 / 2.2.9+
Fix from $1,950 2019-08-02
Webpanel CRITICAL 9.8
CVE-2019-13360EPSS 24%

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge …

No fix yet
Fix from $2,300 2019-07-16
Webpanel HIGH 8.8
CVE-2019-13605EPSS 15%

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveragi…

No fix yet
Fix from $1,950 2019-07-16
GitLab HIGH 7.5
CVE-2018-19584

GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerabili…

Fix: 11.3.11 / 11.4.8+
Fix from $1,950 2019-07-10
Growi HIGH 7.5
CVE-2019-13337

In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used b…

Fix: 3.5.0+
Fix from $1,950 2019-07-09
Prestashop HIGH 7.5
CVE-2019-13461

In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulne…

Fix: after 1.7.5.2
Fix from $1,950 2019-07-09
Thoughtspot HIGH 8.1
CVE-2019-12782

An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write ac…

Fix: after 5.1.1
Fix from $1,950 2019-07-09
Joruri Mail MEDIUM 5.4
CVE-2019-5966

Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and alter/disclose th…

Fix: after 2.1.4
Fix from $1,600 2019-07-05
Youtrack CRITICAL 9.8
CVE-2019-12866

An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed…

Fix: 2018.4.49168+
Fix from $2,300 2019-07-03
Bludit HIGH 8.8
CVE-2019-12742

Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin. This occurs because of bl-kernel/admin/con…

Fix: 3.9.1+
Fix from $1,950 2019-06-05
Manageengine Servicedesk Plus MEDIUM 6.5
CVE-2019-12252EPSS 8%

In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to th…

Fix: after 10.5
Fix from $1,600 2019-05-21
GitLab MEDIUM 5.4
CVE-2019-10108

An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x …

Fix: 11.7.8 / 11.8.4+
Fix from $1,600 2019-05-15
Contour Diabetes MEDIUM 5.3
CVE-2018-18976

An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medica…

Fix: 2.4.30 / 2.5.0+
Fix from $1,600 2019-05-06
GitLab CRITICAL 9.8
CVE-2019-9756

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.…

Fix: 11.6.10 / 11.8.1+
Fix from $2,300 2019-04-17
GitLab MEDIUM 5.3
CVE-2019-9170

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect A…

Fix: 11.6.10 / 11.7.6+
Fix from $1,600 2019-04-17
Je Messenger MEDIUM 6.5
CVE-2019-9921

An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by …

No fix yet
Fix from $1,600 2019-03-29
Shareit MEDIUM 5.3
CVE-2019-9938

The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by th…

Fix: 4.0.42+
Fix from $1,600 2019-03-22
Nervepoint Access Manager CRITICAL 9.4
CVE-2019-6716EPSS 10%

An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote att…

No fix yet
Fix from $2,300 2019-03-21
Monstra HIGH 8.8
CVE-2018-16608

In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&u…

No fix yet
Fix from $1,950 2018-09-10
Proconf MEDIUM 6.5
CVE-2018-16606EPSS 6%

In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and th…

Fix: 6.1+
Fix from $1,600 2018-09-06