Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
Xrt Treasury HIGH 8.8
CVE-2017-3183

Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full ac…

Mitigation only
Fix from $1,950 2018-07-24
Yamldotnet HIGH 7.8
CVE-2018-1000210

YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() …

Fix: after 4.3.2
Fix from $1,950 2018-07-13
Enterprise File Sharing MEDIUM 5.3
CVE-2018-10211

An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a …

Mitigation only
Fix from $1,600 2018-04-25
Nextcloud Server MEDIUM 5.7
CVE-2017-0936

Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check a…

Fix: 11.0.7+
Fix from $1,600 2018-03-28
GitLab HIGH 7.5
CVE-2017-0922

Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in…

Fix: after 10.3.3
Fix from $1,950 2018-03-21
GitLab MEDIUM 6.3
CVE-2017-0882

Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15…

Patch available
Fix from $1,600 2017-03-28
Essex MEDIUM 5.4
CVE-2012-5571

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occu…

Patch available
Fix from $1,600 2012-12-18