Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 7.5 CVE-2019-15725 An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure… GitLab 12.0.8 / 12.1.8+ Fix from $1,9502019-09-16 HIGH 7.5 CVE-2019-14724 In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an e-mail forwarding destination… Webpanel No fix yet Fix from $1,9502019-09-11 MEDIUM 6.5 CVE-2019-14721 In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a target user from phpMyAdmin … Webpanel No fix yet Fix from $1,6002019-09-10 MEDIUM 6.5 CVE-2019-14245 In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) fr… Centos Web Panel No fix yet Fix from $1,6002019-08-21 MEDIUM 6.5 CVE-2019-14246 In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any… Centos Web Panel No fix yet Fix from $1,6002019-08-21 HIGH 7.5 CVE-2019-14932 The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website vi… Humatrix 7 No fix yet Fix from $1,9502019-08-12 HIGH 7.5 CVE-2019-7950 An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An unauthentica… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 HIGH 7.3 CVE-2019-7890 An Insecure Direct Object Reference (IDOR) vulnerability exists in the order processing workflow of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 MEDIUM 5.3 CVE-2019-7864 An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento … Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 MEDIUM 6.5 CVE-2019-7872 An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.… Magento 2.1.18 / 2.2.9+ Fix from $1,6002019-08-02 HIGH 7.5 CVE-2019-7854 An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 can l… Magento 2.1.18 / 2.2.9+ Fix from $1,9502019-08-02 CRITICAL 9.8 CVE-2019-13360EPSS 24% In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge … Webpanel No fix yet Fix from $2,3002019-07-16 HIGH 8.8 CVE-2019-13605EPSS 15% In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by leveragi… Webpanel No fix yet Fix from $1,9502019-07-16 HIGH 7.5 CVE-2018-19584 GitLab EE, versions 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure direct object reference vulnerabili… GitLab 11.3.11 / 11.4.8+ Fix from $1,9502019-07-10 HIGH 7.5 CVE-2019-13337 In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used b… Growi 3.5.0+ Fix from $1,9502019-07-09 HIGH 7.5 CVE-2019-13461 In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulne… Prestashop after 1.7.5.2 Fix from $1,9502019-07-09 HIGH 8.1 CVE-2019-12782 An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low-privilege user with write ac… Thoughtspot after 5.1.1 Fix from $1,9502019-07-09 MEDIUM 5.4 CVE-2019-5966 Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and alter/disclose th… Joruri Mail after 2.1.4 Fix from $1,6002019-07-05 CRITICAL 9.8 CVE-2019-12866 An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed… Youtrack 2018.4.49168+ Fix from $2,3002019-07-03 HIGH 8.8 CVE-2019-12742 Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin. This occurs because of bl-kernel/admin/con… Bludit 3.9.1+ Fix from $1,9502019-06-05 MEDIUM 6.5 CVE-2019-12252EPSS 8% In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to th… Manageengine Servicedesk Plus after 10.5 Fix from $1,6002019-05-21 MEDIUM 5.4 CVE-2019-10108 An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x … GitLab 11.7.8 / 11.8.4+ Fix from $1,6002019-05-15 MEDIUM 5.3 CVE-2018-18976 An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medica… Contour Diabetes 2.4.30 / 2.5.0+ Fix from $1,6002019-05-06 CRITICAL 9.8 CVE-2019-9756 An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and 11.8.… GitLab 11.6.10 / 11.8.1+ Fix from $2,3002019-04-17 MEDIUM 5.3 CVE-2019-9170 An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect A… GitLab 11.6.10 / 11.7.6+ Fix from $1,6002019-04-17 MEDIUM 6.5 CVE-2019-9921 An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that should only be accessible by … Je Messenger No fix yet Fix from $1,6002019-03-29 MEDIUM 5.3 CVE-2019-9938 The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by th… Shareit 4.0.42+ Fix from $1,6002019-03-22 CRITICAL 9.4 CVE-2019-6716EPSS 10% An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote att… Nervepoint Access Manager No fix yet Fix from $2,3002019-03-21 HIGH 8.8 CVE-2018-16608 In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&action=edit&u… Monstra No fix yet Fix from $1,9502018-09-10 MEDIUM 6.5 CVE-2018-16606EPSS 6% In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and th… Proconf 6.1+ Fix from $1,6002018-09-06