Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2024-4341 Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by U… Extreme Xds 3928+ Fix from $1,6002024-07-08 HIGH 7.5 CVE-2024-39321 Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allo… Traefik 2.11.6 / 3.0.4+ Fix from $1,9502024-07-05 CRITICAL 9.8 CVE-2024-39223 An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to … Mitigation only Fix from $2,3002024-07-03 MEDIUM 5.4 CVE-2024-31898 IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypassing authentication using in… Infosphere Information Server Mitigation only Fix from $1,6002024-06-30 MEDIUM 5.4 CVE-2024-5942 The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0 via the 'con… Page And Post Clone 6.1+ Fix from $1,6002024-06-29 CRITICAL 9.8 CVE-2024-1107 Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Contr… Travel Apps 17.0.68+ Fix from $2,3002024-06-27 MEDIUM 6.5 CVE-2023-49112 Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing only its name via the "applicat… Mitigation only Fix from $1,6002024-06-20 MEDIUM 6.5 CVE-2024-37889 MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method … Myfinances 0.4.6+ Fix from $1,6002024-06-14 MEDIUM 6.3 CVE-2024-33373 An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authenti… Bl W1210m Firmware Mitigation only Fix from $1,6002024-06-14 CRITICAL 9.1 CVE-2024-2472 The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on … Latepoint 4.9.91+ Fix from $2,3002024-06-14 MEDIUM 6.5 CVE-2024-5131 An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability a… Lunary 1.2.25+ Fix from $1,6002024-06-06 HIGH 8.8 CVE-2024-5128 An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulne… Lunary 1.2.25+ Fix from $1,9502024-06-06 HIGH 7.5 CVE-2024-5130 An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete … Lunary 1.2.8+ Fix from $1,9502024-06-06 MEDIUM 6.3 CVE-2024-36399 Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php functio… Kanboard 1.2.37+ Fix from $1,6002024-06-06 MEDIUM 5.3 CVE-2024-4750 The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID … Buddyboss 2.6.0+ Fix from $1,6002024-06-04 MEDIUM 5.9 CVE-2024-32045 Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel and team membership when linki… Mattermost Server 8.1.13 / 9.5.4+ Fix from $1,6002024-05-26 MEDIUM 6.5 CVE-2024-5166 An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML mode… Looker Mitigation only Fix from $1,6002024-05-22 MEDIUM 6.5 CVE-2024-4154 In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to… Lunary 1.2.26+ Fix from $1,6002024-05-21 HIGH 8.1 CVE-2024-4151 An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to… Lunary 1.2.25+ Fix from $1,9502024-05-20 MEDIUM 6.5 CVE-2024-4279 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Delet… Tutor Lms 2.7.1+ Fix from $1,6002024-05-16 HIGH 7.1 CVE-2023-40720 An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allo… Fortivoice after 6.4.8 Fix from $1,9502024-05-14 HIGH 8.8 CVE-2024-4819 A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function o… Online Laundry Management System No fix yet Fix from $1,9502024-05-14 HIGH 8.8 CVE-2024-4817 A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code … Online Laundry Management System No fix yet Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-33818 Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter. Mitigation only Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-4538 IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain a user's event ticket… Mitigation only Fix from $1,9502024-05-07 HIGH 7.5 CVE-2024-4537 IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of a… Mitigation only Fix from $1,9502024-05-07 MEDIUM 5.3 CVE-2024-34383 Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects SEOPress: from n/a through 7.7… Mitigation only Fix from $1,6002024-05-06 MEDIUM 5.4 CVE-2024-2346 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions … Filebird 5.6.4+ Fix from $1,6002024-05-02 HIGH 7.5 CVE-2024-24312 SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/UserMod… Mitigation only Fix from $1,9502024-05-01 HIGH 7.5 CVE-2024-33383 Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request u… Novel Plus after 4.3.0 Fix from $1,9502024-04-30