Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
CRITICAL 9.8 CVE-2024-27730 Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the… Friendica Patch available Fix from $2,3002024-08-15 MEDIUM 5.7 CVE-2024-21981 Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in… Mitigation only Fix from $1,6002024-08-13 MEDIUM 6.5 CVE-2024-39642 Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality Not Properly Constrained by ACL… Mitigation only Fix from $1,6002024-08-13 MEDIUM 5.3 CVE-2024-7658 A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the f… Projectsend Patch available Fix from $1,6002024-08-12 HIGH 8.1 CVE-2024-3035 A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 1… GitLab 17.0.6 / 17.1.4+ Fix from $1,9502024-08-08 HIGH 8.8 CVE-2024-6357 Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence. Arcsight Intelligence 6.4.13+ Fix from $1,9502024-08-06 MEDIUM 5.3 CVE-2024-41254 An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attacke… Litestream after 0.3.13 Fix from $1,6002024-07-31 HIGH 8.8 CVE-2024-38701 Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4. Academy Lms 2.0.5+ Fix from $1,9502024-07-22 MEDIUM 6.5 CVE-2024-34457 On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone'… Streampark 2.1.4+ Fix from $1,6002024-07-22 MEDIUM 5.4 CVE-2024-5977 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… Givewp 3.14.0+ Fix from $1,6002024-07-19 CRITICAL 9.6 CVE-2024-5619 Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Con… Mitigation only Fix from $2,3002024-07-18 HIGH 8.1 CVE-2024-38447 NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbit… Advisor Network No fix yet Fix from $1,9502024-07-17 MEDIUM 6.5 CVE-2024-38446 NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of tha… Advisor Network No fix yet Fix from $1,6002024-07-17 MEDIUM 5.4 CVE-2024-39900 OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin … Observability 2.14+ Fix from $1,6002024-07-09 MEDIUM 5.4 CVE-2024-39901 OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugin… Observability 2.14+ Fix from $1,6002024-07-09 MEDIUM 6.5 CVE-2023-3286 A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in una… Easyappointments 1.5.0+ Fix from $1,6002024-07-09 HIGH 8.8 CVE-2023-3287 A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege e… Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 8.8 CVE-2023-3288 A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege … Easyappointments 1.5.0+ Fix from $1,9502024-07-09 MEDIUM 6.5 CVE-2023-3289 A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in… Easyappointments 1.5.0+ Fix from $1,6002024-07-09 MEDIUM 5.0 CVE-2023-3290 A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauth… Easyappointments 1.5.0+ Fix from $1,6002024-07-09 HIGH 8.1 CVE-2023-38055 A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (incl… Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 8.1 CVE-2023-38050 A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (includi… Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 8.1 CVE-2023-38051 A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (se… Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 8.1 CVE-2023-38052 A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). Th… Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 8.1 CVE-2023-38053 A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (in… Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 8.1 CVE-2023-38054 A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (custo… Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 8.1 CVE-2023-38047 A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (i… Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 8.1 CVE-2023-38048 A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider)… Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 8.1 CVE-2023-38049 A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any … Easyappointments 1.5.0+ Fix from $1,9502024-07-09 HIGH 7.7 CVE-2023-3285 A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This r… Mitigation only Fix from $1,9502024-07-09