Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
MEDIUM 5.3 CVE-2021-24374 The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image gallery and allows users to com… Jetpack 9.8+ Fix from $1,6002021-06-21 MEDIUM 6.5 CVE-2021-22906 Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated user… End To End Encryption 1.5.3 / 1.6.3+ Fix from $1,6002021-06-11 MEDIUM 5.5 CVE-2021-31970 Windows TCP/IP Driver Security Feature Bypass Vulnerability Windows 10 Patch available Fix from $1,6002021-06-08 CRITICAL 9.1 CVE-2021-32654 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to receive … Nextcloud Server 19.0.11 / 20.0.10+ Fix from $2,3002021-06-01 MEDIUM 6.5 CVE-2021-24318 The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any … Listeo 1.6.11+ Fix from $1,6002021-06-01 HIGH 8.1 CVE-2020-36126 Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation. PAXSTOR… Paxstore after 7.0.8_20200511171508 Fix from $1,9502021-05-07 HIGH 8.8 CVE-2020-23722 An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id… Fuel Cms No fix yet Fix from $1,9502021-03-10 MEDIUM 6.5 CVE-2021-21324 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi 9.5.4+ Fix from $1,6002021-03-08 MEDIUM 5.7 CVE-2021-21255 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi Patch available Fix from $1,6002021-03-02 MEDIUM 5.3 CVE-2021-21022 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object reference (IDOR) in … Magento 2.3.6+ Fix from $1,6002021-02-11 MEDIUM 5.7 CVE-2020-13462 Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA. Securetrack Mitigation only Fix from $1,6002021-02-09 MEDIUM 5.3 CVE-2020-16194 An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to an… Op\'art Devis 4.0.2+ Fix from $1,6002021-02-04 MEDIUM 5.3 CVE-2021-26024EPSS 19% The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for an… Favorites 1.0.2+ Fix from $1,6002021-02-03 HIGH 7.5 CVE-2020-23449 newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthor… Newbee Mall Patch available Fix from $1,9502021-01-26 MEDIUM 5.3 CVE-2020-29446 Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulner… Crucible 4.8.5+ Fix from $1,6002021-01-18 MEDIUM 5.3 CVE-2021-21012 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR)… Magento Commerce after 2.3.6 Fix from $1,6002021-01-13 HIGH 8.1 CVE-2021-21013 Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR)… Magento after 2.4.1 Fix from $1,9502021-01-13 HIGH 7.5 CVE-2020-35849 An issue was discovered in MantisBT before 2.24.4. An incorrect access check in bug_revision_view_page.php allows an unprivileged attacker to view th… Mantisbt 2.24.4+ Fix from $1,9502020-12-30 MEDIUM 5.3 CVE-2020-29156 The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetc… Woocommerce 4.7.0+ Fix from $1,6002020-12-27 MEDIUM 6.5 CVE-2020-26175 In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile info… Business Workflow 1.18.1+ Fix from $1,6002020-12-18 MEDIUM 5.3 CVE-2020-26178 In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated. Business Workflow 1.18.1+ Fix from $1,6002020-12-18 HIGH 7.5 CVE-2020-20183 Insecure direct object reference vulnerability in Zyxel’s P1302-T10 v3 with firmware version 2.00(ABBX.3) and earlier allows attackers to gain privil… P1302 T10 V3 Firmware Mitigation only Fix from $1,9502020-12-14 MEDIUM 6.5 CVE-2020-26068 A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to gene… Roomos 9.10.3 / 9.12.4+ Fix from $1,6002020-11-18 MEDIUM 6.5 CVE-2020-27742 An Insecure Direct Object Reference vulnerability in Citadel WebCit through 926 allows authenticated remote attackers to read someone else's emails v… Webcit after 926 Fix from $1,6002020-10-28 MEDIUM 5.3 CVE-2020-16240 GE Digital APM Classic, Versions 4.4 and prior. An insecure direct object reference (IDOR) vulnerability allows user account data to be downloaded in… Asset Performance Management Classic after 4.4 Fix from $1,6002020-09-23 MEDIUM 5.3 CVE-2020-23446 Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API Workforce Optimization No fix yet Fix from $1,6002020-09-22 HIGH 8.6 CVE-2020-15958 An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to acce… 1crm after 8.6.7 Fix from $1,9502020-09-18 MEDIUM 6.5 CVE-2020-10779 Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege ch… Cloudforms Mitigation only Fix from $1,6002020-08-11 MEDIUM 5.3 CVE-2020-13923EPSS 5% IDOR vulnerability in the order processing feature from ecommerce component of Apache OFBiz before 17.12.04 Ofbiz 17.12.04+ Fix from $1,6002020-07-15 CRITICAL 9.8 CVE-2019-15310EPSS 8% An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could … Linkplay No fix yet Fix from $2,3002020-07-01