Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
CRITICAL 9.8 CVE-2023-38965 Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI. Lost And Found Information System No fix yet Fix from $2,3002023-11-03 HIGH 8.8 CVE-2023-46478 An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter. Minical No fix yet Fix from $1,9502023-10-30 MEDIUM 5.3 CVE-2023-3869 The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment functi… Wpdiscuz after 7.6.3 Fix from $1,6002023-10-20 MEDIUM 5.3 CVE-2023-3998 The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in… Wpdiscuz after 7.6.3 Fix from $1,6002023-10-20 HIGH 8.1 CVE-2022-24401 Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TD… Tetra\ Mitigation only Fix from $1,9502023-10-19 MEDIUM 5.9 CVE-2022-24400 A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero. Tetra\ Mitigation only Fix from $1,6002023-10-19 CRITICAL 9.8 CVE-2023-43668 Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  some se… Inlong after 1.8.0 Fix from $2,3002023-10-16 MEDIUM 6.5 CVE-2023-45393 An indirect object reference (IDOR) in GRANDING UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to access sensitive information v… Utime Master No fix yet Fix from $1,6002023-10-13 MEDIUM 6.5 CVE-2023-45396 An Insecure Direct Object Reference (IDOR) vulnerability leads to events profiles access in Elenos ETG150 FM transmitter running on version 3.12. Etg150 Firmware Mitigation only Fix from $1,6002023-10-11 CRITICAL 9.1 CVE-2023-44981 Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quoru… Zookeeper 3.7.2 / 3.8.3+ Fix from $2,3002023-10-11 MEDIUM 6.5 CVE-2023-44249 An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer… Fortianalyzer 7.2.4+ Fix from $1,6002023-10-10 HIGH 8.8 CVE-2023-42455 Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API admin… Wazuh Dashboard 4.4.2+ Fix from $1,9502023-10-09 MEDIUM 6.7 CVE-2023-26237 An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM. Epp Firmware 8.00.22.0010+ Fix from $1,6002023-10-05 MEDIUM 6.5 CVE-2023-2544 Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an authenticated user could chan… Peix Mitigation only Fix from $1,6002023-10-03 MEDIUM 5.4 CVE-2023-32669 Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other… Buddyboss Mitigation only Fix from $1,6002023-10-03 MEDIUM 6.5 CVE-2023-4099 The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions t… Qsige Mitigation only Fix from $1,6002023-10-03 MEDIUM 6.5 CVE-2023-4101 The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. A… Qsige Mitigation only Fix from $1,6002023-10-03 HIGH 8.8 CVE-2023-4934 Authorization Bypass Through User-Controlled Key vulnerability in Usta AYBS allows Authentication Abuse, Authentication Bypass. This issue affects A… Aybs 1.0.3+ Fix from $1,9502023-09-27 MEDIUM 5.3 CVE-2023-44205 Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before… Cyber Protect 15+ Fix from $1,6002023-09-27 CRITICAL 9.1 CVE-2023-44206 Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux… Cyber Protect 15+ Fix from $2,3002023-09-27 HIGH 8.1 CVE-2023-44154 Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux… Cyber Protect 15+ Fix from $1,9502023-09-27 MEDIUM 6.5 CVE-2023-42334 An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user par… Crew No fix yet Fix from $1,6002023-09-20 HIGH 8.8 CVE-2023-4213 The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.4.5. T… Simplr Registration Form Plus\+ after 2.4.5 Fix from $1,9502023-09-13 MEDIUM 5.3 CVE-2023-41368 The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by … S\/4 Hana Mitigation only Fix from $1,6002023-09-12 HIGH 8.8 CVE-2020-10130 SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system. Searchblox 9.1+ Fix from $1,9502023-09-06 MEDIUM 5.5 CVE-2023-4587 An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local attacker to obtain registered… Zem800 Firmware Mitigation only Fix from $1,6002023-09-04 MEDIUM 6.5 CVE-2023-38201 A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allo… Enterprise Linux Patch available Fix from $1,6002023-08-25 HIGH 7.5 CVE-2023-32078 Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions prior to 0.17.1 and 0.18.6 in … Netmaker 0.17.1+ Fix from $1,9502023-08-24 MEDIUM 6.7 CVE-2023-27576 An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, al… Phplist Patch available Fix from $1,6002023-08-18 HIGH 8.8 CVE-2023-28481 An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergra… Tigergraph No fix yet Fix from $1,9502023-08-14