Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 8.8 CVE-2024-48217 An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation. Mitigation only Fix from $1,9502024-11-01 CRITICAL 9.8 CVE-2024-37277 Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACL… Paid Memberships Pro 3.0.5+ Fix from $2,3002024-11-01 CRITICAL 9.1 CVE-2024-10654 A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functiona… Lr350 Firmware No fix yet Fix from $2,3002024-11-01 HIGH 7.5 CVE-2024-51066 An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unaut… Beauty Parlour Management System No fix yet Fix from $1,9502024-10-31 MEDIUM 5.3 CVE-2024-9700 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all… Forminator Forms 1.36.1+ Fix from $1,6002024-10-31 MEDIUM 6.5 CVE-2024-7473 An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability all… Lunary Patch available Fix from $1,6002024-10-29 HIGH 8.1 CVE-2024-7474 In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by ma… Lunary 1.3.4+ Fix from $1,9502024-10-29 CRITICAL 9.8 CVE-2024-50483 Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: fr… Meetup after 0.1 Fix from $2,3002024-10-28 HIGH 7.5 CVE-2024-10439 The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specifi… Ehrd Ctms 10.8+ Fix from $1,9502024-10-28 HIGH 8.8 CVE-2024-9637 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, a… Wpschoolpress 2.2.11+ Fix from $1,9502024-10-26 CRITICAL 9.8 CVE-2024-10121 A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Inter… Radar after 1.0.8 Fix from $2,3002024-10-18 CRITICAL 9.8 CVE-2024-9263 The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privileg… Mitigation only Fix from $2,3002024-10-17 CRITICAL 9.8 CVE-2024-9862 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, … Otp Verification With Firebase 3.6.1+ Fix from $2,3002024-10-17 HIGH 8.8 CVE-2024-9215 The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct O… Mitigation only Fix from $1,9502024-10-17 MEDIUM 5.9 CVE-2023-32189 Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys Mitigation only Fix from $1,6002024-10-16 HIGH 7.7 CVE-2024-8040 An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated… Mitigation only Fix from $1,9502024-10-16 MEDIUM 6.5 CVE-2023-7286 The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes … Mitigation only Fix from $1,6002024-10-16 CRITICAL 9.1 CVE-2024-49388 Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) befo… Cyber Protect after 15 Fix from $2,3002024-10-15 HIGH 8.8 CVE-2024-9687 The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficie… Wp 2fa With Telegram 3.1+ Fix from $1,9502024-10-15 MEDIUM 6.7 CVE-2024-47495 An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of t… Junos Os Evolved 21.2+ Fix from $1,6002024-10-11 MEDIUM 6.5 CVE-2024-7041 An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint… Open Webui No fix yet Fix from $1,6002024-10-09 HIGH 8.8 CVE-2024-47316 Authorization Bypass Through User-Controlled Key vulnerability in Dimitri Grassi Salon booking system salon-booking-system.This issue affects Salon b… Salon Booking System 10.9.1+ Fix from $1,9502024-10-05 MEDIUM 6.5 CVE-2024-47657 This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An authenticated remote attacker co… Net Back Office 5.5.002+ Fix from $1,6002024-10-04 MEDIUM 5.3 CVE-2024-20513 A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthentic… Meraki Mx65 Firmware 18.211.2+ Fix from $1,6002024-10-02 MEDIUM 6.8 CVE-2021-37577 Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 th… Mitigation only Fix from $1,6002024-10-01 MEDIUM 5.3 CVE-2024-39319 aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 20… Aimeos Frontend Controller 2020.10.15 / 2021.10.8+ Fix from $1,6002024-09-26 HIGH 8.8 CVE-2024-8290 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direc… Frontend Manager For Woocommerce Along With Bookings Subscription Listings Compatible 6.7.13+ Fix from $1,9502024-09-25 CRITICAL 9.8 CVE-2024-8485 The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.… Rest Api To Miniprogram after 4.7.1 Fix from $2,3002024-09-25 CRITICAL 9.8 CVE-2024-8791 The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation i… Charitable 1.8.1.15+ Fix from $2,3002024-09-24 MEDIUM 6.5 CVE-2024-45806 Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy hea… Envoy 1.28.7 / 1.29.9+ Fix from $1,6002024-09-20