Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2021-24374
The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to com…
Jetpack
9.8+
MEDIUM 6.5
CVE-2021-22906
Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated user…
End To End Encryption
1.5.3 / 1.6.3+
MEDIUM 5.5
CVE-2021-31970
Windows TCP/IP Driver Security Feature Bypass Vulnerability
Windows 10
Patch available
CRITICAL 9.1
CVE-2021-32654
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive …
Nextcloud Server
19.0.11 / 20.0.10+
MEDIUM 6.5
CVE-2021-24318
The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any …
Listeo
1.6.11+
HIGH 8.1
CVE-2020-36126
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation. PAXSTOR…
Paxstore
after 7.0.8_20200511171508
HIGH 8.8
CVE-2020-23722
An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id…
Fuel Cms
No fix yet
MEDIUM 6.5
CVE-2021-21324
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
9.5.4+
MEDIUM 5.7
CVE-2021-21255
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
Patch available
MEDIUM 5.3
CVE-2021-21022
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in …
Magento
2.3.6+
MEDIUM 5.7
CVE-2020-13462
Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.
Securetrack
Mitigation only
MEDIUM 5.3
CVE-2020-16194
An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to an…
Op\'art Devis
4.0.2+
MEDIUM 5.3
CVE-2021-26024EPSS 19%
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for an…
Favorites
1.0.2+
HIGH 7.5
CVE-2020-23449
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthor…
Newbee Mall
Patch available
MEDIUM 5.3
CVE-2020-29446
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulner…
Crucible
4.8.5+
MEDIUM 5.3
CVE-2021-21012
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR)…
Magento Commerce
after 2.3.6
HIGH 8.1
CVE-2021-21013
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR)…
Magento
after 2.4.1
HIGH 7.5
CVE-2020-35849
An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view th…
Mantisbt
2.24.4+
MEDIUM 5.3
CVE-2020-29156
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetc…
Woocommerce
4.7.0+
MEDIUM 6.5
CVE-2020-26175
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile info…
Business Workflow
1.18.1+
MEDIUM 5.3
CVE-2020-26178
In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.
Business Workflow
1.18.1+
HIGH 7.5
CVE-2020-20183
Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privil…
P1302 T10 V3 Firmware
Mitigation only
MEDIUM 6.5
CVE-2020-26068
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to gene…
Roomos
9.10.3 / 9.12.4+
MEDIUM 6.5
CVE-2020-27742
An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails v…
Webcit
after 926
MEDIUM 5.3
CVE-2020-16240
GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in…
Asset Performance Management Classic
after 4.4
MEDIUM 5.3
CVE-2020-23446
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API
Workforce Optimization
No fix yet
HIGH 8.6
CVE-2020-15958
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to acce…
1crm
after 8.6.7
MEDIUM 6.5
CVE-2020-10779
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege ch…
Cloudforms
Mitigation only
MEDIUM 5.3
CVE-2020-13923EPSS 5%
IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04
Ofbiz
17.12.04+
CRITICAL 9.8
CVE-2019-15310EPSS 8%
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could …
Linkplay
No fix yet