Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-45893
An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to…
Customer Portal
Mitigation only
HIGH 7.5
CVE-2023-51503
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This …
Woopayments
6.7.0+
MEDIUM 5.3
CVE-2023-46646
Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check r…
Enterprise Server
3.7.19 / 3.8.12+
MEDIUM 6.5
CVE-2023-49765
Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating…
Rate My Post
3.4.2+
MEDIUM 6.5
CVE-2023-47191
Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership…
Youzify
1.2.3+
HIGH 7.5
CVE-2023-32747
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a …
Woocommerce Bookings
after 1.15.78
MEDIUM 6.5
CVE-2023-32799
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addres…
Shipping Multiple Addresses
after 3.8.3
HIGH 7.5
CVE-2023-35914
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a throug…
Woocommerce Subscriptions
5.1.3+
HIGH 7.5
CVE-2023-35916
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This …
Woopayments
5.9.1+
HIGH 8.1
CVE-2023-35876
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a thro…
Woocommerce Square
3.8.2+
HIGH 8.1
CVE-2023-36520
Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a th…
Editorial Calendar
3.8.0+
MEDIUM 6.5
CVE-2023-41796
Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue…
Sunshine Photo Cart
3.0+
MEDIUM 6.5
CVE-2023-46311
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a …
Wpdiscuz
7.6.4+
HIGH 7.5
CVE-2023-37871
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.
Woocommerce Gocardless
2.5.7+
MEDIUM 5.4
CVE-2023-38513
Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engi…
Photo Engine
6.2.6+
CRITICAL 9.8
CVE-2023-6929
EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur when the application provides direct access…
Etl3100 Firmware
Mitigation only
MEDIUM 6.5
CVE-2022-43450
Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.
Stream
after 3.9.2
HIGH 7.5
CVE-2023-49812
Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album…
Wp Photo Album Plus
after 8.5.02.005
MEDIUM 5.3
CVE-2023-46701
Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allow…
Mattermost Server
after 9.2.1
HIGH 8.8
CVE-2023-48641
Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a …
Archer
6.13.0.3 / 6.14.0.1.2+
MEDIUM 5.3
CVE-2023-6341
Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other…
Cms360
Mitigation only
HIGH 7.5
CVE-2023-49298
OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can r…
Openzfs
after 2.1.13
MEDIUM 6.5
CVE-2023-33706
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp o…
Sysaid
23.2.15 / 23.2.50+
MEDIUM 5.4
CVE-2023-47316
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls…
Headwind Mdm
No fix yet
HIGH 7.5
CVE-2023-38884
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote att…
Opensis
Mitigation only
MEDIUM 6.5
CVE-2023-43900
Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive dat…
Emsigner
No fix yet
MEDIUM 6.8
CVE-2023-46446
An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulati…
Asyncssh
2.14.1+
MEDIUM 5.4
CVE-2023-5544
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
Moodle
3.9.24 / 3.11.17+
HIGH 8.8
CVE-2023-45380
In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can…
Order Duplicator
1.1.8+
MEDIUM 6.5
CVE-2023-41356
NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can expl…
Tronclass Ilearn
Mitigation only