Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 6.5 CVE-2022-0613 Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8. Fedora 1.19.8+ Fix from $1,6002022-02-16 MEDIUM 6.5 CVE-2021-46249 An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd4… Scratchoauth2 2021-04-12+ Fix from $1,6002022-02-15 MEDIUM 5.3 CVE-2022-0512 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. Url Parse 1.5.6+ Fix from $1,6002022-02-14 MEDIUM 6.5 CVE-2021-3813 Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2. Chatwoot after 2.1.1 Fix from $1,6002022-02-09 MEDIUM 6.5 CVE-2021-25096 The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL Country Blocker 2.26.5+ Fix from $1,6002022-02-07 CRITICAL 9.8 CVE-2022-22832EPSS 14% An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request. Tessa No fix yet Fix from $2,3002022-02-06 HIGH 7.5 CVE-2021-41608 A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attac… Selectsurvey.net 5.052.000+ Fix from $1,9502022-01-28 HIGH 7.5 CVE-2022-22828 An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via… Synaman 5.0+ Fix from $1,9502022-01-27 MEDIUM 5.3 CVE-2022-23856 An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as f… Enterprise Identity Cloud No fix yet Fix from $1,6002022-01-24 MEDIUM 6.6 CVE-2022-0266 Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v. Live Helper Chat 3.92+ Fix from $1,6002022-01-19 HIGH 7.5 CVE-2021-3965EPSS 5% Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of print job previews. Designjet T920 Cr355a Firmware Mitigation only Fix from $1,9502022-01-14 HIGH 7.5 CVE-2021-3852 growi is vulnerable to Authorization Bypass Through User-Controlled Key Growi after 4.4.7 Fix from $1,9502022-01-12 CRITICAL 9.8 CVE-2021-45428EPSS 57% TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including H… Tlr 2005ksh Firmware No fix yet Fix from $2,3002022-01-03 HIGH 7.3 CVE-2021-44160 Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege b… Carinal Tien Hospital Health Report System Mitigation only Fix from $1,9502021-12-29 MEDIUM 6.5 CVE-2021-40579 https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected by: Incorrect Access Control. … Online Enrollment Management System No fix yet Fix from $1,6002021-12-28 HIGH 8.1 CVE-2021-24739 The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by … Logo Carousel 3.4.2+ Fix from $1,9502021-12-21 HIGH 7.5 CVE-2021-43828 PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) h… Patrowlmanager 1.7.7+ Fix from $1,9502021-12-14 MEDIUM 5.9 CVE-2021-43820 Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve… Seafile Server 8.0.8 / 8.0.15+ Fix from $1,6002021-12-14 CRITICAL 9.8 CVE-2021-44949 glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php. Glfusion No fix yet Fix from $2,3002021-12-14 MEDIUM 5.9 CVE-2021-3964 elgg is vulnerable to Authorization Bypass Through User-Controlled Key Elgg 3.3.22+ Fix from $1,6002021-12-01 MEDIUM 6.5 CVE-2021-3992 kimai2 is vulnerable to Improper Access Control Kimai2 1.16.2+ Fix from $1,6002021-12-01 MEDIUM 6.5 CVE-2021-36329 Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially expl… Emc Streaming Data Platform 1.3+ Fix from $1,6002021-11-30 HIGH 8.8 CVE-2021-24892 Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrar… Advanced Forms 1.6.9+ Fix from $1,9502021-11-23 HIGH 7.5 CVE-2021-22951 Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concre… Concrete Cms 8.5.7+ Fix from $1,9502021-11-19 HIGH 7.5 CVE-2021-22967 In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Convers… Concrete Cms 8.5.7+ Fix from $1,9502021-11-19 MEDIUM 6.5 CVE-2021-3380 Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print Invoice Func… H8 Ssrms No fix yet Fix from $1,6002021-11-10 MEDIUM 5.3 CVE-2021-24840 The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve the posts to display in one of… Squaretype 3.0.4+ Fix from $1,6002021-11-08 HIGH 7.5 CVE-2021-41305 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an … Jira 8.13.12+ Fix from $1,9502021-10-26 HIGH 7.5 CVE-2021-41306 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure … Jira 8.13.12 / 8.20.0+ Fix from $1,9502021-10-26 HIGH 7.5 CVE-2021-41307 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private f… Jira 8.13.12 / 8.20.0+ Fix from $1,9502021-10-26