Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.5 CVE-2022-40319EPSS 7% The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a w… Listserv No fix yet Fix from $1,9502023-01-17 MEDIUM 5.3 CVE-2022-4806 Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-28 MEDIUM 5.4 CVE-2022-4811 Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-28 MEDIUM 6.5 CVE-2022-4812 Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-28 MEDIUM 5.3 CVE-2022-4798 Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-28 MEDIUM 6.5 CVE-2022-4799 Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-28 MEDIUM 5.4 CVE-2022-4802 Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-28 HIGH 8.8 CVE-2022-4803 Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,9502022-12-28 HIGH 7.8 CVE-2022-46179 LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to s… Liuos Patch available Fix from $1,9502022-12-28 CRITICAL 9.8 CVE-2022-4686 Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0. Memos 0.9.0+ Fix from $2,3002022-12-23 HIGH 7.5 CVE-2022-3805 The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions … Jeg Elementor Kit 2.5.7+ Fix from $1,9502022-12-22 MEDIUM 5.4 CVE-2022-31683 Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body inclu… Concourse 6.7.9 / 7.8.3+ Fix from $1,6002022-12-19 MEDIUM 6.5 CVE-2022-3876 A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This … Passwordstate No fix yet Fix from $1,6002022-12-19 MEDIUM 5.3 CVE-2022-4097 The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (lik… All In One Security 5.0.8+ Fix from $1,6002022-12-12 MEDIUM 6.5 CVE-2022-38765 Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized acce… Vitrea View 7.8+ Fix from $1,6002022-12-09 HIGH 8.8 CVE-2022-2808 Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping In… Prens Student Information System 2.1.11+ Fix from $1,9502022-12-02 HIGH 7.5 CVE-2022-43326 An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attacke… Omnia Mpx Node Firmware 1.5.0+ Fix from $1,9502022-11-29 HIGH 7.5 CVE-2022-24187 The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. O… Ourphoto No fix yet Fix from $1,9502022-11-28 HIGH 8.1 CVE-2022-3589 An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker woul… Appwash Mitigation only Fix from $1,9502022-11-21 HIGH 8.8 CVE-2022-43492 Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress. Wpdiscuz Mitigation only Fix from $1,9502022-11-18 MEDIUM 5.3 CVE-2022-44005 An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionali… Backclick No fix yet Fix from $1,6002022-11-16 HIGH 8.8 CVE-2021-36906 Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. Quiz And Survey Master after 7.3.6 Fix from $1,9502022-11-03 MEDIUM 6.5 CVE-2022-39945 An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may … Fortimail after 7.0.3 Fix from $1,6002022-11-02 HIGH 7.5 CVE-2022-39018 Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a know… Hubshare 3.3.11.3+ Fix from $1,9502022-10-31 CRITICAL 9.8 CVE-2022-31692 Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatc… Spring Security 5.6.9 / 5.7.5+ Fix from $2,3002022-10-31 MEDIUM 5.4 CVE-2022-36966 Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object re… Orion Platform 2020.2.6+ Fix from $1,6002022-10-20 HIGH 7.5 CVE-2022-33077 An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint. Nopcommerce after 4.50.2 Fix from $1,9502022-10-19 HIGH 7.5 CVE-2022-41479 The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /… Asp.net Web Forms Controls No fix yet Fix from $1,9502022-10-18 MEDIUM 6.5 CVE-2022-2828 In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR)… Octopus Server after 2022.3.10586 Fix from $1,6002022-10-13 MEDIUM 5.3 CVE-2022-1613 The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which m… Restricted Site Access 7.3.2+ Fix from $1,6002022-09-26