Skip to main content

CWE archive

CWE-639 CVEs

Programmatic archive

2,259 CVEs tagged with CWE-639172 Critical, 711 High, 1,218 Medium, 152 Low, 6 Unrated.

CVE-2024-27630

Published Apr 8, 2024

Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file funct…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31296

Published Apr 7, 2024

Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31291

Published Apr 7, 2024

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6523

Published Apr 5, 2024

Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse. This issue affects Extreme XDS: before 3914.

CVSS 8.8 · High

CVE-2024-31095

Published Mar 31, 2024

Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.1.0.

CVSS 5.3 · Medium

CVE-2024-30543

Published Mar 31, 2024

Authorization Bypass Through User-Controlled Key vulnerability in UPQODE Whizz.This issue affects Whizzy: from n/a through 1.1.18.

CVSS 6.5 · Medium

CVE-2024-30513

Published Mar 29, 2024

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30507

Published Mar 29, 2024

Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through 4.7.7.

CVSS 2.7 · Low

CVE-2024-29024

Published Mar 29, 2024

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vul…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29020

Published Mar 29, 2024

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1313

Published Mar 26, 2024

It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE request to /api/snapshots/<key…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2024-29194

Published Mar 24, 2024

OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. Speci…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1604

Published Mar 18, 2024

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2577

Published Mar 18, 2024

A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employ…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2576

Published Mar 18, 2024

A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of the file /update-admin.php. The…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2575

Published Mar 18, 2024

A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. Affected by this issue is some unknown functionality of th…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2574

Published Mar 18, 2024

A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edi…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36238

Published Mar 13, 2024

Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1640

Published Mar 13, 2024

The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin for WordPress is vulnerable to unauthorized modification of d…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0839

Published Mar 13, 2024

The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2022.0222 due to missing validation on the user cont…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6969

Published Mar 13, 2024

The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the user_meta shortcode due to miss…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,726-1,750 of 2,259 CVEsPage 70 of 91