Total
655 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-38051 | 1 Easyappointments | 1 Easyappointments | 2024-08-26 | 9.9 Critical |
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation. | ||||
CVE-2023-38048 | 1 Easyappointments | 1 Easyappointments | 2024-08-26 | 9.9 Critical |
A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in unauthorized access and unauthorized data manipulation. | ||||
CVE-2023-38054 | 1 Easyappointments | 1 Easyappointments | 2024-08-26 | 9.9 Critical |
A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data manipulation. | ||||
CVE-2023-38047 | 1 Easyappointments | 1 Easyappointments | 2024-08-26 | 8.5 High |
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | ||||
CVE-2023-38052 | 1 Easyappointments | 1 Easyappointments | 2024-08-26 | 9.9 Critical |
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation. | ||||
CVE-2023-38049 | 1 Easyappointments | 1 Easyappointments | 2024-08-26 | 9.9 Critical |
A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | ||||
CVE-2024-2574 | 2024-08-22 | 7.3 High | ||
A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit-task.php. The manipulation of the argument task_id leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257077 was assigned to this vulnerability. | ||||
CVE-2024-6534 | 1 Monospace | 1 Directus | 2024-08-19 | 4.1 Medium |
Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not in the PATCH request. When chained with CVE-2024-6533, it could result in account takeover. | ||||
CVE-2024-6357 | 1 Opentext | 1 Arcsight Intelligence | 2024-08-19 | 6.3 Medium |
Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence. | ||||
CVE-2024-43315 | 1 Checkoutplugins | 1 Stripe Payments For Woocommerce | 2024-08-19 | 7.5 High |
Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1. | ||||
CVE-2024-43288 | 2024-08-19 | 4.3 Medium | ||
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4. | ||||
CVE-2024-43239 | 2024-08-19 | 4.3 Medium | ||
Authorization Bypass Through User-Controlled Key vulnerability in Masteriyo Masteriyo - LMS.This issue affects Masteriyo - LMS: from n/a through 1.11.4. | ||||
CVE-2024-43266 | 2024-08-19 | 5.4 Medium | ||
Authorization Bypass Through User-Controlled Key vulnerability in WP Job Portal.This issue affects WP Job Portal: from n/a through 2.1.6. | ||||
CVE-2024-27730 | 1 Friendica | 1 Friendica | 2024-08-19 | 9.8 Critical |
Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature. | ||||
CVE-2024-27630 | 2024-08-16 | N/A | ||
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function. | ||||
CVE-2023-51141 | 2024-08-16 | 6.5 Medium | ||
An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication & Authorization component | ||||
CVE-2023-6523 | 2024-08-15 | 8.8 High | ||
Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse.This issue affects Extreme XDS: before 3914. | ||||
CVE-2024-21981 | 1 Amd | 3 Athlon, Epyc, Ryzen | 2024-08-15 | 5.7 Medium |
Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity. | ||||
CVE-2024-38701 | 1 Kodezen | 1 Academy Lms | 2024-08-14 | 4.3 Medium |
Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4. | ||||
CVE-2024-7658 | 1 Projectsend | 1 Projectsend | 2024-08-13 | 5.3 Medium |
A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may be initiated remotely. Upgrading to version r1720 is able to address this issue. The patch is named eb5a04774927e5855b9d0e5870a2aae5a3dc5a08. It is recommended to upgrade the affected component. |