Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.5 CVE-2022-31295 An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts. Online Discussion Forum Site No fix yet Fix from $1,9502022-06-16 MEDIUM 6.5 CVE-2022-31027 OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets u… Oauthenticator 15.0.0+ Fix from $1,6002022-06-09 CRITICAL 9.1 CVE-2022-1996 Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0. Fedora 2.16.0 / 3.8.0+ Fix from $2,3002022-06-08 HIGH 7.5 CVE-2022-1949 An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progr… 389 Directory Server after 2.0.0 Fix from $1,9502022-06-02 CRITICAL 9.8 CVE-2022-30495 In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change… Automotive Shop Management System No fix yet Fix from $2,3002022-05-26 MEDIUM 5.4 CVE-2022-29434 Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete e… Spiffy Calendar after 4.9.0 Fix from $1,6002022-05-20 MEDIUM 5.3 CVE-2022-27247 onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth… Winhotel.mx No fix yet Fix from $1,6002022-05-13 MEDIUM 5.3 CVE-2022-1352 Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and … GitLab 14.8.6 / 14.9.4+ Fix from $1,6002022-05-11 MEDIUM 6.5 CVE-2022-29008 An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensit… Bus Pass Management System No fix yet Fix from $1,6002022-05-11 HIGH 7.5 CVE-2022-28986 LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which… 2 Factor Authentication No fix yet Fix from $1,9502022-05-10 MEDIUM 6.5 CVE-2022-23061 In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) v… Shopizer after 2.17.0 Fix from $1,6002022-05-01 MEDIUM 6.5 CVE-2022-1461 Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1. Openemr 6.1.0.1+ Fix from $1,6002022-04-25 HIGH 8.3 CVE-2022-1459 Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1. Openemr 6.1.0.1+ Fix from $1,9502022-04-25 HIGH 7.5 CVE-2022-26665 An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sens… Odyssey Portal 17.1.20+ Fix from $1,9502022-04-18 HIGH 7.5 CVE-2022-22190 An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to levera… Paragon Active Assurance Control Center Mitigation only Fix from $1,9502022-04-14 HIGH 8.1 CVE-2021-46416 Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie … Sunny Tripower Firmware No fix yet Fix from $1,9502022-04-07 CRITICAL 9.1 CVE-2022-1165 The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests… Blackhole For Bad Bots 3.3.2+ Fix from $2,3002022-04-04 HIGH 7.1 CVE-2022-22331 IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details cause… Partner Engagement Manager Patch available Fix from $1,9502022-04-01 MEDIUM 6.5 CVE-2021-38362 In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecur… Archer 6.9.3.0.1+ Fix from $1,6002022-03-30 MEDIUM 5.3 CVE-2022-26254 WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to … Wowonder No fix yet Fix from $1,6002022-03-27 HIGH 7.5 CVE-2021-43957 Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vuln… Crucible 4.8.9+ Fix from $1,9502022-03-16 HIGH 8.1 CVE-2022-25471 An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas v… Openemr Mitigation only Fix from $1,9502022-03-03 MEDIUM 5.4 CVE-2021-41111 Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticate… Rundeck 3.3.15 / 3.4.5+ Fix from $1,6002022-02-28 HIGH 7.5 CVE-2022-0732 The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating … Copy9 Mitigation only Fix from $1,9502022-02-24 MEDIUM 6.5 CVE-2022-0731 Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0. Dolibarr Erp\/crm 16.0.0+ Fix from $1,6002022-02-23 CRITICAL 9.8 CVE-2022-0691 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. Url Parse 1.5.9+ Fix from $2,3002022-02-21 CRITICAL 9.1 CVE-2022-0686 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. Url Parse 1.5.8+ Fix from $2,3002022-02-20 MEDIUM 5.3 CVE-2022-24979 An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does no… Varnishcache 2.0.1+ Fix from $1,6002022-02-19 MEDIUM 5.3 CVE-2022-25336 Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image… Ez Platform Kernel 1.3.12 / 7.5.26+ Fix from $1,6002022-02-18 MEDIUM 5.3 CVE-2022-0639 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. Url Parse 1.5.7+ Fix from $1,6002022-02-17