Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-40319EPSS 7%
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a w…
Listserv
No fix yet
MEDIUM 5.3
CVE-2022-4806
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
MEDIUM 5.4
CVE-2022-4811
Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.
Memos
0.9.1+
MEDIUM 6.5
CVE-2022-4812
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
MEDIUM 5.3
CVE-2022-4798
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
MEDIUM 6.5
CVE-2022-4799
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
MEDIUM 5.4
CVE-2022-4802
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
HIGH 8.8
CVE-2022-4803
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
HIGH 7.8
CVE-2022-46179
LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to s…
Liuos
Patch available
CRITICAL 9.8
CVE-2022-4686
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
Memos
0.9.0+
HIGH 7.5
CVE-2022-3805
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions …
Jeg Elementor Kit
2.5.7+
MEDIUM 5.4
CVE-2022-31683
Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can send a request with body inclu…
Concourse
6.7.9 / 7.8.3+
MEDIUM 6.5
CVE-2022-3876
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This …
Passwordstate
No fix yet
MEDIUM 5.3
CVE-2022-4097
The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (lik…
All In One Security
5.0.8+
MEDIUM 6.5
CVE-2022-38765
Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized acce…
Vitrea View
7.8+
HIGH 8.8
CVE-2022-2808
Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping In…
Prens Student Information System
2.1.11+
HIGH 7.5
CVE-2022-43326
An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attacke…
Omnia Mpx Node Firmware
1.5.0+
HIGH 7.5
CVE-2022-24187
The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. O…
Ourphoto
No fix yet
HIGH 8.1
CVE-2022-3589
An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker woul…
Appwash
Mitigation only
HIGH 8.8
CVE-2022-43492
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
Wpdiscuz
Mitigation only
MEDIUM 5.3
CVE-2022-44005
An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionali…
Backclick
No fix yet
HIGH 8.8
CVE-2021-36906
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress.
Quiz And Survey Master
after 7.3.6
MEDIUM 6.5
CVE-2022-39945
An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may …
Fortimail
after 7.0.3
HIGH 7.5
CVE-2022-39018
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a know…
Hubshare
3.3.11.3+
CRITICAL 9.8
CVE-2022-31692
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatc…
Spring Security
5.6.9 / 5.7.5+
MEDIUM 5.4
CVE-2022-36966
Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object re…
Orion Platform
2020.2.6+
HIGH 7.5
CVE-2022-33077
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.
Nopcommerce
after 4.50.2
HIGH 7.5
CVE-2022-41479
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /…
Asp.net Web Forms Controls
No fix yet
MEDIUM 6.5
CVE-2022-2828
In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR)…
Octopus Server
after 2022.3.10586
MEDIUM 5.3
CVE-2022-1613
The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which m…
Restricted Site Access
7.3.2+