Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-31295
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.
Online Discussion Forum Site
No fix yet
MEDIUM 6.5
CVE-2022-31027
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets u…
Oauthenticator
15.0.0+
CRITICAL 9.1
CVE-2022-1996
Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.
Fedora
2.16.0 / 3.8.0+
HIGH 7.5
CVE-2022-1949
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progr…
389 Directory Server
after 2.0.0
CRITICAL 9.8
CVE-2022-30495
In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change…
Automotive Shop Management System
No fix yet
MEDIUM 5.4
CVE-2022-29434
Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete e…
Spiffy Calendar
after 4.9.0
MEDIUM 5.3
CVE-2022-27247
onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth…
Winhotel.mx
No fix yet
MEDIUM 5.3
CVE-2022-1352
Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and …
GitLab
14.8.6 / 14.9.4+
MEDIUM 6.5
CVE-2022-29008
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensit…
Bus Pass Management System
No fix yet
HIGH 7.5
CVE-2022-28986
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which…
2 Factor Authentication
No fix yet
MEDIUM 6.5
CVE-2022-23061
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) v…
Shopizer
after 2.17.0
MEDIUM 6.5
CVE-2022-1461
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
Openemr
6.1.0.1+
HIGH 8.3
CVE-2022-1459
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
Openemr
6.1.0.1+
HIGH 7.5
CVE-2022-26665
An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sens…
Odyssey Portal
17.1.20+
HIGH 7.5
CVE-2022-22190
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to levera…
Paragon Active Assurance Control Center
Mitigation only
HIGH 8.1
CVE-2021-46416
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie …
Sunny Tripower Firmware
No fix yet
CRITICAL 9.1
CVE-2022-1165
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests…
Blackhole For Bad Bots
3.3.2+
HIGH 7.1
CVE-2022-22331
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details cause…
Partner Engagement Manager
Patch available
MEDIUM 6.5
CVE-2021-38362
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecur…
Archer
6.9.3.0.1+
MEDIUM 5.3
CVE-2022-26254
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to …
Wowonder
No fix yet
HIGH 7.5
CVE-2021-43957
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vuln…
Crucible
4.8.9+
HIGH 8.1
CVE-2022-25471
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas v…
Openemr
Mitigation only
MEDIUM 5.4
CVE-2021-41111
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticate…
Rundeck
3.3.15 / 3.4.5+
HIGH 7.5
CVE-2022-0732
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating …
Copy9
Mitigation only
MEDIUM 6.5
CVE-2022-0731
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
Dolibarr Erp\/crm
16.0.0+
CRITICAL 9.8
CVE-2022-0691
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
Url Parse
1.5.9+
CRITICAL 9.1
CVE-2022-0686
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
Url Parse
1.5.8+
MEDIUM 5.3
CVE-2022-24979
An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does no…
Varnishcache
2.0.1+
MEDIUM 5.3
CVE-2022-25336
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image…
Ez Platform Kernel
1.3.12 / 7.5.26+
MEDIUM 5.3
CVE-2022-0639
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
Url Parse
1.5.7+