Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.5 CVE-2023-45893 An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to… Customer Portal Mitigation only Fix from $1,9502024-01-02 HIGH 7.5 CVE-2023-51503 Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This … Woopayments 6.7.0+ Fix from $1,9502023-12-31 MEDIUM 5.3 CVE-2023-46646 Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via the "Get a check r… Enterprise Server 3.7.19 / 3.8.12+ Fix from $1,6002023-12-21 MEDIUM 6.5 CVE-2023-49765 Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating… Rate My Post 3.4.2+ Fix from $1,6002023-12-21 MEDIUM 6.5 CVE-2023-47191 Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership… Youzify 1.2.3+ Fix from $1,6002023-12-21 HIGH 7.5 CVE-2023-32747 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a … Woocommerce Bookings after 1.15.78 Fix from $1,9502023-12-21 MEDIUM 6.5 CVE-2023-32799 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addres… Shipping Multiple Addresses after 3.8.3 Fix from $1,6002023-12-21 HIGH 7.5 CVE-2023-35914 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a throug… Woocommerce Subscriptions 5.1.3+ Fix from $1,9502023-12-20 HIGH 7.5 CVE-2023-35916 Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This … Woopayments 5.9.1+ Fix from $1,9502023-12-20 HIGH 8.1 CVE-2023-35876 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a thro… Woocommerce Square 3.8.2+ Fix from $1,9502023-12-20 HIGH 8.1 CVE-2023-36520 Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a th… Editorial Calendar 3.8.0+ Fix from $1,9502023-12-20 MEDIUM 6.5 CVE-2023-41796 Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue… Sunshine Photo Cart 3.0+ Fix from $1,6002023-12-20 MEDIUM 6.5 CVE-2023-46311 Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a … Wpdiscuz 7.6.4+ Fix from $1,6002023-12-20 HIGH 7.5 CVE-2023-37871 Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6. Woocommerce Gocardless 2.5.7+ Fix from $1,9502023-12-20 MEDIUM 5.4 CVE-2023-38513 Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engi… Photo Engine 6.2.6+ Fix from $1,6002023-12-20 CRITICAL 9.8 CVE-2023-6929 EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur when the application provides direct access… Etl3100 Firmware Mitigation only Fix from $2,3002023-12-19 MEDIUM 6.5 CVE-2022-43450 Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2. Stream after 3.9.2 Fix from $1,6002023-12-19 HIGH 7.5 CVE-2023-49812 Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album… Wp Photo Album Plus after 8.5.02.005 Fix from $1,9502023-12-19 MEDIUM 5.3 CVE-2023-46701 Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allow… Mattermost Server after 9.2.1 Fix from $1,6002023-12-12 HIGH 8.8 CVE-2023-48641 Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a … Archer 6.13.0.3 / 6.14.0.1.2+ Fix from $1,9502023-12-12 MEDIUM 5.3 CVE-2023-6341 Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other… Cms360 Mitigation only Fix from $1,6002023-11-30 HIGH 7.5 CVE-2023-49298 OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can r… Openzfs after 2.1.13 Fix from $1,9502023-11-24 MEDIUM 6.5 CVE-2023-33706 SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp o… Sysaid 23.2.15 / 23.2.50+ Fix from $1,6002023-11-24 MEDIUM 5.4 CVE-2023-47316 Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls… Headwind Mdm No fix yet Fix from $1,6002023-11-22 HIGH 7.5 CVE-2023-38884 An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote att… Opensis Mitigation only Fix from $1,9502023-11-20 MEDIUM 6.5 CVE-2023-43900 Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive dat… Emsigner No fix yet Fix from $1,6002023-11-14 MEDIUM 6.8 CVE-2023-46446 An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulati… Asyncssh 2.14.1+ Fix from $1,6002023-11-14 MEDIUM 5.4 CVE-2023-5544 Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk. Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 HIGH 8.8 CVE-2023-45380 In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can… Order Duplicator 1.1.8+ Fix from $1,9502023-11-07 MEDIUM 6.5 CVE-2023-41356 NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can expl… Tronclass Ilearn Mitigation only Fix from $1,6002023-11-03