Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
CRITICAL 9.1 CVE-2019-19755 ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of al… Mitigation only Fix from $2,3002024-04-30 HIGH 7.6 CVE-2024-28320 Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthori… Hospital Management System No fix yet Fix from $1,9502024-04-29 HIGH 8.8 CVE-2024-4294 A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is s… Doctor Appointment Management System No fix yet Fix from $1,9502024-04-27 CRITICAL 9.1 CVE-2024-33668 An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker c… Zammad 6.3.0+ Fix from $2,3002024-04-26 HIGH 8.8 CVE-2024-32808 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9. Profilegrid 5.8.0+ Fix from $1,9502024-04-24 MEDIUM 5.3 CVE-2024-32823 Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rat… Rate My Post 3.4.5+ Fix from $1,6002024-04-24 HIGH 8.8 CVE-2024-32772 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9. Profilegrid 5.8.0+ Fix from $1,9502024-04-24 HIGH 8.8 CVE-2024-32166 Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction … Webid No fix yet Fix from $1,9502024-04-19 HIGH 7.5 CVE-2024-32683 Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through 2.… Wp Ultimate Review 2.3.0+ Fix from $1,9502024-04-19 HIGH 8.1 CVE-2024-1626 An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, within the project update endpoint… Lunary 1.0.0+ Fix from $1,9502024-04-16 MEDIUM 5.4 CVE-2023-45808 iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In othe… Itop 2.7.10 / 3.0.4+ Fix from $1,6002024-04-15 MEDIUM 6.9 CVE-2024-22439 A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series products. This vulnerability could be exploited to ga… No fix yet Fix from $1,6002024-04-15 MEDIUM 6.5 CVE-2023-51141 An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization compone… Biotime No fix yet Fix from $1,6002024-04-11 MEDIUM 6.5 CVE-2024-1625 An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allowing unauthorized deletion of … Lunary Patch available Fix from $1,6002024-04-10 MEDIUM 5.4 CVE-2024-1289 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.… Learnpress 4.2.6.4+ Fix from $1,6002024-04-09 CRITICAL 9.8 CVE-2023-6317 A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without … Webos No fix yet Fix from $2,3002024-04-09 HIGH 7.5 CVE-2024-27630 Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the t… Savane 3.13+ Fix from $1,9502024-04-08 CRITICAL 9.1 CVE-2024-31815 In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh Ex200 Firmware No fix yet Fix from $2,3002024-04-08 HIGH 7.1 CVE-2024-31291 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6. Profilegrid 5.7.7+ Fix from $1,9502024-04-07 MEDIUM 5.4 CVE-2024-31296 Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1… Bookingpress 1.0.82+ Fix from $1,6002024-04-07 HIGH 8.8 CVE-2023-6523 Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse. This issue affects Extreme XD… Mitigation only Fix from $1,9502024-04-05 MEDIUM 5.4 CVE-2024-3139 A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue… Computer Laboratory Management System No fix yet Fix from $1,6002024-04-01 MEDIUM 6.5 CVE-2024-30543 Authorization Bypass Through User-Controlled Key vulnerability in UPQODE Whizz.This issue affects Whizzy: from n/a through 1.1.18. Mitigation only Fix from $1,6002024-03-31 MEDIUM 5.3 CVE-2024-31095 Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.… No fix yet Fix from $1,6002024-03-31 MEDIUM 6.5 CVE-2024-30513 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2. Profilegrid 5.7.3+ Fix from $1,6002024-03-29 MEDIUM 5.3 CVE-2024-29020 JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive informa… Jumpserver 3.10.6+ Fix from $1,6002024-03-29 MEDIUM 5.3 CVE-2024-29024 JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Dire… Jumpserver 3.10.6+ Fix from $1,6002024-03-29 MEDIUM 6.5 CVE-2024-1313 It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE … Mitigation only Fix from $1,6002024-03-26 HIGH 8.3 CVE-2024-29194 OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data wit… Oneuptime 7.0.1815+ Fix from $1,9502024-03-24 MEDIUM 6.8 CVE-2024-1604 Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and ma… Control M 9.0.20.238 / 9.0.21.201+ Fix from $1,6002024-03-18