Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.5 CVE-2023-37543 Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php.… Cacti 1.2.6+ Fix from $1,9502023-08-10 CRITICAL 9.8 CVE-2023-2958 Authorization Bypass Through User-Controlled Key vulnerability in Origin Software ATS Pro allows Authentication Abuse, Authentication Bypass. This i… Ats Pro 20230714+ Fix from $2,3002023-07-17 MEDIUM 6.5 CVE-2023-2190 An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.… GitLab 15.11.10 / 16.0.6+ Fix from $1,6002023-07-13 HIGH 8.8 CVE-2023-3105 The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the… Learndash after 4.6.0 Fix from $1,9502023-07-12 MEDIUM 5.3 CVE-2023-30956 A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if th… Foundry Comments 2.267.0+ Fix from $1,6002023-07-10 MEDIUM 5.3 CVE-2023-3219EPSS 8% The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, all… Eventon 2.1.2+ Fix from $1,6002023-07-10 CRITICAL 9.8 CVE-2023-37242 Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-vol… Emui Mitigation only Fix from $2,3002023-07-06 HIGH 8.8 CVE-2022-42175 Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker to change the password and hostname of other custom… Solusvm Mitigation only Fix from $1,9502023-07-05 HIGH 8.8 CVE-2023-3063 The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. Thi… Sp Project \& Document Manager after 4.67 Fix from $1,9502023-06-30 MEDIUM 5.5 CVE-2022-48505 This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the … macOS 13.0+ Fix from $1,6002023-06-28 MEDIUM 5.5 CVE-2023-32352 A logic issue was addressed with improved checks. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6… Ipados 9.5 / 11.7.7+ Fix from $1,6002023-06-23 HIGH 8.8 CVE-2023-23679 Authorization Bypass Through User-Controlled Key vulnerability in JS Help Desk js-support-ticket allows Accessing Functionality Not Properly Constrai… Jshelpdesk after 2.7.7 Fix from $1,9502023-06-23 MEDIUM 6.5 CVE-2023-26428 Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other use… Open Xchange Appsuite Backend 7.10.6 / 8.11.0+ Fix from $1,6002023-06-20 HIGH 7.8 CVE-2023-21131 In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitigations due to a logic error i… Android Patch available Fix from $1,9502023-06-15 HIGH 7.5 CVE-2023-34000 Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions. Stripe Payment Gateway 7.4.1+ Fix from $1,9502023-06-14 CRITICAL 9.8 CVE-2023-3048 Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass. This issue affect… Lockcell Firmware 15.0+ Fix from $2,3002023-06-13 MEDIUM 6.5 CVE-2023-1889 The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to imp… Directorist after 7.5.4 Fix from $1,6002023-06-09 MEDIUM 6.5 CVE-2023-0688 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' shortcode in versions up to, a… Metform Elementor Contact Form Builder after 3.3.1 Fix from $1,6002023-06-09 HIGH 8.8 CVE-2021-33223 An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file. Seeddms No fix yet Fix from $1,9502023-06-07 HIGH 8.8 CVE-2023-0985 An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2… Mbconnect24 after 2.13.3 Fix from $1,9502023-06-06 MEDIUM 6.5 CVE-2023-33956 Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to an Insecure direc… Kanboard 1.2.30+ Fix from $1,6002023-06-05 HIGH 8.1 CVE-2023-3066 Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including admi… Amxgt 100 after 1.3.20 Fix from $1,9502023-06-05 HIGH 8.1 CVE-2023-32310 DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and delete system messages is vulner… Dataease 1.18.7+ Fix from $1,9502023-06-01 CRITICAL 9.1 CVE-2022-36247 Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za. Shop Beat Media Player 3.2.57+ Fix from $2,3002023-05-30 HIGH 8.8 CVE-2023-2883 Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass. This issue affect… Cbot Core 4.0.3.4 / 4.0.3.7+ Fix from $1,9502023-05-25 HIGH 8.8 CVE-2023-2065 Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication… Cargo Tracking System 3558f28+ Fix from $1,9502023-05-24 HIGH 8.8 CVE-2023-2702 Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authentication Abuse, Authenticati… Competition Management System 23.07+ Fix from $1,9502023-05-23 CRITICAL 9.8 CVE-2023-2713 Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows… Rental Module 23.05.15+ Fix from $2,3002023-05-20 CRITICAL 9.8 CVE-2023-2276 The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in … Wcfm Membership after 2.10.7 Fix from $2,3002023-05-20 HIGH 7.2 CVE-2023-2548 The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due … Registrationmagic after 5.2.0.5 Fix from $1,9502023-05-16