Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 8.1 CVE-2021-39225 Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows ano… Deck 1.2.9 / 1.4.5+ Fix from $1,9502021-10-25 MEDIUM 5.4 CVE-2021-36387 In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially craft… Yellowfin 9.6.1+ Fix from $1,6002021-10-14 HIGH 7.5 CVE-2021-36388 In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability e… Yellowfin 9.6.1+ Fix from $1,9502021-10-14 HIGH 7.5 CVE-2021-36389 In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploita… Yellowfin 9.6.1+ Fix from $1,9502021-10-14 HIGH 7.5 CVE-2021-20599 Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC iQ-R series Safety CPU R08/16/… R08sfcpu Firmware Mitigation only Fix from $1,9502021-10-14 HIGH 8.1 CVE-2021-41129 Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmati… Panel 1.6.2+ Fix from $1,9502021-10-06 HIGH 7.5 CVE-2021-41120 sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was… Paypal 1.2.4 / 1.3.1+ Fix from $1,9502021-10-05 MEDIUM 5.3 CVE-2021-37331 Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade Lic… Booking Core No fix yet Fix from $1,6002021-10-04 HIGH 7.5 CVE-2021-37777 Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site owner just… Gila Cms No fix yet Fix from $1,9502021-10-04 HIGH 8.8 CVE-2021-41847 An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials assigned to… Infinias Access Control after 6.7.10708.0 Fix from $1,9502021-10-01 HIGH 8.8 CVE-2021-41298 ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on use… Ecs Router Controller Ecs Firmware Mitigation only Fix from $1,9502021-09-30 CRITICAL 9.8 CVE-2021-41301 ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files using an HTTP GET request. T… Ecs Router Controller Ecs Firmware Mitigation only Fix from $2,3002021-09-30 HIGH 8.8 CVE-2021-36874 Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5). Ulisting after 2.0.5 Fix from $1,9502021-09-27 MEDIUM 5.4 CVE-2021-29773 IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an i… Security Guardium Patch available Fix from $1,6002021-09-15 MEDIUM 6.5 CVE-2021-38624 Windows Key Storage Provider Security Feature Bypass Vulnerability Windows 10 Patch available Fix from $1,6002021-09-15 HIGH 8.8 CVE-2021-40355 A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (Al… Teamcenter Visualization 12.4.0.8 / 13.0.0.7+ Fix from $1,9502021-09-14 CRITICAL 9.8 CVE-2021-37184 A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker could change the the password of… Industrial Edge Management 1.3+ Fix from $2,3002021-09-14 HIGH 7.5 CVE-2021-37628 Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares i… Richdocuments 3.8.4 / 4.2.1+ Fix from $1,9502021-09-07 MEDIUM 6.5 CVE-2021-37630 Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed … Circles 0.19.5 / 0.20.11+ Fix from $1,6002021-09-07 MEDIUM 6.5 CVE-2021-37631 Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In aff… Deck 1.2.9 / 1.4.4+ Fix from $1,6002021-09-07 HIGH 8.8 CVE-2021-36032 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerabil… Adobe Commerce after 2.4.2 Fix from $1,9502021-09-01 MEDIUM 6.5 CVE-2021-40352EPSS 10% OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users. Openemr No fix yet Fix from $1,6002021-09-01 HIGH 7.2 CVE-2021-22023 The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to v… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 HIGH 7.5 CVE-2021-24562 The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue… Lifterlms 4.21.2+ Fix from $1,9502021-08-23 MEDIUM 6.5 CVE-2021-37709 Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log… Shopware 6.4.3.1+ Fix from $1,6002021-08-16 MEDIUM 5.4 CVE-2021-37212 The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote at… Flygo 1.91.1+ Fix from $1,6002021-08-09 HIGH 8.8 CVE-2021-37214 The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, re… Flygo 1.91.1+ Fix from $1,9502021-08-09 HIGH 8.1 CVE-2021-36801 Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed i… Akaunting after 2.1.12 Fix from $1,9502021-08-04 MEDIUM 5.4 CVE-2021-24473 The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_image capability (by default aut… User Profile Picture 2.6.0+ Fix from $1,6002021-08-02 HIGH 7.5 CVE-2021-32744 Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gai… Online 4.2.17-1 / 6.4.9-5+ Fix from $1,9502021-07-21