Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
CRITICAL 9.8 CVE-2024-2577 A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown c… Employee Task Management System Mitigation only Fix from $2,3002024-03-18 CRITICAL 9.8 CVE-2024-2574 A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this vulnerability is an unknown … Employee Task Management System Mitigation only Fix from $2,3002024-03-18 CRITICAL 9.8 CVE-2024-2575 A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. Affected by this issue is so… Employee Task Management System Mitigation only Fix from $2,3002024-03-18 CRITICAL 9.8 CVE-2024-2576 A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of t… Employee Task Management System Mitigation only Fix from $2,3002024-03-18 MEDIUM 6.5 CVE-2023-36483 Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android  version 1.16.18 and earlier and MASmobile Classic iOS v… Masmobile Asp.net Services after 1.16.18 Fix from $1,6002024-03-16 MEDIUM 6.5 CVE-2023-36238 Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter. Bagisto No fix yet Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-1640 The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to … Contact Form Builder 2.10.2+ Fix from $1,6002024-03-13 MEDIUM 5.3 CVE-2024-0839 The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missi… Feedwordpress 2024.0428+ Fix from $1,6002024-03-13 CRITICAL 9.1 CVE-2024-27302 go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - which is an array of domains allo… Go Zero 1.4.4+ Fix from $2,3002024-03-06 HIGH 7.8 CVE-2024-1470 Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Cod… Client Login Extension Mitigation only Fix from $1,9502024-02-29 MEDIUM 5.3 CVE-2024-25983 Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise ava… Moodle 4.1.9 / 4.2.6+ Fix from $1,6002024-02-19 MEDIUM 6.5 CVE-2023-49339 Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData e… Banner after 9.17 Fix from $1,6002024-02-13 MEDIUM 5.3 CVE-2024-0421 The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a … Mappress Maps For Wordpress 2.88.16+ Fix from $1,6002024-02-12 HIGH 8.8 CVE-2023-6724 Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking… Hearing Tracking System 7.0+ Fix from $1,9502024-02-09 HIGH 8.8 CVE-2023-6515 Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abuse. This issue affects MİA-ME… Mia Med 1.0.7+ Fix from $1,9502024-02-08 MEDIUM 6.5 CVE-2023-47022 Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV … Terminal Handler Mitigation only Fix from $1,6002024-02-06 MEDIUM 5.3 CVE-2024-1075 The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions u… Minimal Coming Soon \& Maintenance Mode after 2.37 Fix from $1,6002024-02-05 HIGH 8.1 CVE-2024-22305 Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This iss… Kali Forms 2.3.37+ Fix from $1,9502024-01-31 MEDIUM 5.3 CVE-2023-7199 The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and pr… Relevanssi after 2.25.0 Fix from $1,6002024-01-29 HIGH 7.5 CVE-2024-23747 The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vuln… Modernanet Hospital Management System 2024 No fix yet Fix from $1,9502024-01-29 HIGH 7.5 CVE-2024-0580 Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extr… Sinergia Mitigation only Fix from $1,9502024-01-18 MEDIUM 6.5 CVE-2023-36235 An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter. Qloapps 1.6.0+ Fix from $1,6002024-01-17 MEDIUM 6.5 CVE-2023-6824 The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to r… Wp Customer Area 8.2.1+ Fix from $1,6002024-01-16 CRITICAL 9.8 CVE-2024-22206 Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth(… Javascript 4.29.3+ Fix from $2,3002024-01-12 CRITICAL 9.8 CVE-2023-6875EPSS 90% The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized … Post Smtp after 2.8.7 Fix from $2,3002024-01-11 MEDIUM 5.4 CVE-2023-48783EPSS 22% An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, v… Fortiportal 7.0.7 / 7.2.2+ Fix from $1,6002024-01-10 HIGH 8.8 CVE-2023-49251 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected applicatio… Simatic Cn 4100 Firmware 2.7+ Fix from $1,9502024-01-09 CRITICAL 9.8 CVE-2024-0264EPSS 18% A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of t… Clinic Queuing System No fix yet Fix from $2,3002024-01-07 CRITICAL 9.8 CVE-2023-51502 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Strip… Woocommerce Stripe after 7.6.1 Fix from $2,3002024-01-05 HIGH 7.5 CVE-2023-45892 An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive custome… Insight Mitigation only Fix from $1,9502024-01-02