Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
CRITICAL 9.8 CVE-2023-31182 EasyTor Applications – Authorization Bypass - EasyTor Applications may allow authorization bypass via unspecified method. Easytor No fix yet Fix from $2,3002023-05-08 MEDIUM 5.4 CVE-2023-30216 Insecure permissions in the updateUserInfo function of newbee-mall before commit 1f2c2dfy allows attackers to obtain user account information. Newbee Mall 2022-10-27+ Fix from $1,6002023-05-04 HIGH 8.1 CVE-2023-28656 NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: So… Nginx Api Connectivity Manager 1.3.0 / 1.5.0+ Fix from $1,9502023-05-03 MEDIUM 6.5 CVE-2023-1125 The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an a… Ruby Help Desk 1.3.4+ Fix from $1,6002023-05-02 HIGH 8.8 CVE-2023-2260 Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304. Alf 2.0-m4-2304+ Fix from $1,9502023-04-24 MEDIUM 6.5 CVE-2022-48313 The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may… Emui No fix yet Fix from $1,6002023-04-16 HIGH 7.5 CVE-2018-17449 An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers co… GitLab 11.1.7 / 11.2.4+ Fix from $1,9502023-04-15 HIGH 7.5 CVE-2018-17455 An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive … GitLab 11.1.7 / 11.2.4+ Fix from $1,9502023-04-15 MEDIUM 6.5 CVE-2022-45175 An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/… Vdesk after 018 Fix from $1,6002023-04-14 MEDIUM 6.5 CVE-2023-0967 Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that sh… Bhima No fix yet Fix from $1,6002023-04-05 MEDIUM 6.5 CVE-2023-1749 The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could se… Nxal 100 Firmware Mitigation only Fix from $1,6002023-04-04 HIGH 7.1 CVE-2023-1750 The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could re… Nxal 100 Firmware Mitigation only Fix from $1,9502023-04-04 HIGH 8.1 CVE-2023-26984 An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted re… Peppermint No fix yet Fix from $1,9502023-03-29 MEDIUM 5.3 CVE-2023-24842 HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial … Oaklouds Mailsherlock Mitigation only Fix from $1,6002023-03-27 MEDIUM 6.5 CVE-2023-24834 WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this… Tronclass Ilearn 1.52.29198+ Fix from $1,6002023-03-27 MEDIUM 6.5 CVE-2023-24625 Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack. Faveo Servicedesk No fix yet Fix from $1,6002023-03-24 HIGH 7.1 CVE-2023-28686 Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attac… Fedora 0.2.3 / 0.3.2+ Fix from $1,9502023-03-24 HIGH 8.8 CVE-2023-1462 Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Authentication Bypass, Authentic… Digikent 23.03.20+ Fix from $1,9502023-03-21 HIGH 8.8 CVE-2023-0865 The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete an… Woocommerce Multiple Customer Addresses \& Shipping 21.7+ Fix from $1,9502023-03-20 MEDIUM 5.4 CVE-2023-1463 Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. Teampass 3.0.0.23+ Fix from $1,6002023-03-17 MEDIUM 6.5 CVE-2023-28109 Play With Docker is a browser-based Docker playground. Versions 0.0.2 and prior are vulnerable to domain hijacking. Because CORS configuration was no… Play With Docker Patch available Fix from $1,6002023-03-16 MEDIUM 5.3 CVE-2021-36400 In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. Moodle 3.9.8 / 3.10.5+ Fix from $1,6002023-03-06 HIGH 7.5 CVE-2023-25403 CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format cha… Yf Exam No fix yet Fix from $1,9502023-03-03 HIGH 8.8 CVE-2023-0882 Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abu… Single Connect 2.16.1+ Fix from $1,9502023-02-17 MEDIUM 5.3 CVE-2023-25160 Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access th… Mail 1.11.8 / 1.12.9+ Fix from $1,6002023-02-13 HIGH 7.5 CVE-2022-34138 Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive informati… Baby Camera Firmware Mitigation only Fix from $1,9502023-02-03 CRITICAL 9.8 CVE-2023-0558 The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in v… Contentstudio 1.2.6+ Fix from $2,3002023-01-27 HIGH 8.1 CVE-2023-0550 The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due… Quick Restaurant Menu 2.1.0+ Fix from $1,9502023-01-27 MEDIUM 6.5 CVE-2021-36539 Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL… Canvas Learning Management Service 2022-10-15+ Fix from $1,6002023-01-26 HIGH 8.8 CVE-2022-45927 An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication … Opentext Extended Ecm 22.4+ Fix from $1,9502023-01-18