Vulnerability index

Browse CVEs

1,777 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Authorization Bypass (IDOR)CWE-639 × clear
HIGH 8.8 CVE-2017-3183 Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authenticated user to gain full ac… Xrt Treasury Mitigation only Fix from $1,9502018-07-24 HIGH 7.8 CVE-2018-1000210 YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() … Yamldotnet after 4.3.2 Fix from $1,9502018-07-13 MEDIUM 5.3 CVE-2018-10211 An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization when listing the history of another user via a … Enterprise File Sharing Mitigation only Fix from $1,6002018-04-25 MEDIUM 5.7 CVE-2017-0936 Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check a… Nextcloud Server 11.0.7+ Fix from $1,6002018-03-28 HIGH 7.5 CVE-2017-0922 Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in… GitLab after 10.3.3 Fix from $1,9502018-03-21 MEDIUM 6.3 CVE-2017-0882 Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15… GitLab Patch available Fix from $1,6002017-03-28 MEDIUM 5.4 CVE-2012-5571 A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occu… Essex Patch available Fix from $1,6002012-12-18