Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.4 CVE-2024-45614 Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwar… Puma 5.6.9 / 6.4.3+ Fix from $1,6002024-09-19 HIGH 7.5 CVE-2024-46982EPSS 59% Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non… Next.js 13.5.7 / 14.2.10+ Fix from $1,9502024-09-17 HIGH 7.5 CVE-2024-47047 An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting i… Powermail after 12.4.0 Fix from $1,9502024-09-17 HIGH 7.5 CVE-2024-46937 An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SA… Secure Authentication Server 1.9.040924+ Fix from $1,9502024-09-16 MEDIUM 5.3 CVE-2022-3459 The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due t… Woocommerce Multiple Free Gift after 1.2.3 Fix from $1,6002024-09-14 MEDIUM 6.5 CVE-2024-6087 An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. The vulnerability allows an at… Lunary 1.4.9+ Fix from $1,6002024-09-13 HIGH 7.5 CVE-2024-3305 Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensiti… Soliclub 4.4.0 / 5.2.1+ Fix from $1,9502024-09-12 HIGH 7.5 CVE-2024-3306 Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control… Soliclub 4.4.0 / 5.2.1+ Fix from $1,9502024-09-12 CRITICAL 9.8 CVE-2024-27113 An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view se… Soplanning 1.52.02+ Fix from $2,3002024-09-11 MEDIUM 6.5 CVE-2024-45786 This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints. An authenticated remote atta… Aim Star Mitigation only Fix from $1,6002024-09-11 MEDIUM 6.5 CVE-2023-44254 An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version … Fortianalyzer 7.2.5+ Fix from $1,6002024-09-10 CRITICAL 10.0 CVE-2024-45032 A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.… Mitigation only Fix from $2,3002024-09-10 MEDIUM 6.5 CVE-2024-8601 This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An auth… Back Office Software 1.0.0+ Fix from $1,6002024-09-09 HIGH 8.8 CVE-2024-8428 The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all … Forumwp after 2.0.2 Fix from $1,9502024-09-06 HIGH 7.5 CVE-2024-1744 Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive… Accord Ors 7.3.2.1+ Fix from $1,9502024-09-06 CRITICAL 9.8 CVE-2024-8292 The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up… Wp Recall 16.26.9+ Fix from $2,3002024-09-06 MEDIUM 5.4 CVE-2024-8123 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and in… Wp Extended 3.0.9+ Fix from $1,6002024-09-04 MEDIUM 5.3 CVE-2024-45232 An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the confirmationAction, resulting… Powermail 7.5.0 / 8.5.0+ Fix from $1,6002024-08-29 MEDIUM 6.5 CVE-2024-40395 An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of acces… Thingworx Mitigation only Fix from $1,6002024-08-27 HIGH 7.1 CVE-2024-43916 Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from … Zephyr Project Manager 3.3.103+ Fix from $1,9502024-08-26 MEDIUM 6.5 CVE-2024-8158 A bug in the 9p authentication implementation within lib9p allows an attacker with an existing valid user within the configured auth server to impers… Lib9p 2024-08-24+ Fix from $1,6002024-08-25 MEDIUM 6.5 CVE-2024-7848 The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … User Private Files 2.1.1+ Fix from $1,6002024-08-22 MEDIUM 5.3 CVE-2024-43350 Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6… Mitigation only Fix from $1,6002024-08-18 HIGH 7.5 CVE-2024-43315 Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Str… Mitigation only Fix from $1,9502024-08-18 CRITICAL 9.8 CVE-2024-43322 Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from … Zephyr Project Manager 3.3.101+ Fix from $2,3002024-08-18 HIGH 8.1 CVE-2024-43288 Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4. Wpforo Forum 2.3.5+ Fix from $1,9502024-08-18 HIGH 8.8 CVE-2024-43266 Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue affects WP Job Portal: from n/a … Wp Job Portal 2.1.9+ Fix from $1,9502024-08-18 HIGH 8.1 CVE-2024-43239 Authorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo -… Masteriyo 1.11.5+ Fix from $1,9502024-08-18 MEDIUM 6.5 CVE-2024-42463 Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the Sy… Upkeeper Manager 5.1.10+ Fix from $1,6002024-08-16 MEDIUM 6.5 CVE-2024-42464 Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the Sy… Upkeeper Manager 5.1.10+ Fix from $1,6002024-08-16