Total
1315 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-22471 | 1 Nextcloud | 1 Deck | 2024-11-21 | N/A | 3.5 LOW |
|
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the Nextcloud Deck app is upgraded to 1.6.5 or 1.7.3 or 1.8.2.
|
|||||
| CVE-2023-1750 | 1 Getnexx | 8 Nxal-100, Nxal-100 Firmware, Nxg-100b and 5 more | 2024-11-21 | N/A | 7.1 HIGH |
|
The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could retrieve device history, set device settings, and retrieve device information.
|
|||||
| CVE-2023-1749 | 1 Getnexx | 8 Nxal-100, Nxal-100 Firmware, Nxg-100b and 5 more | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could send API requests that the affected devices would execute.
|
|||||
| CVE-2023-1463 | 1 Teampass | 1 Teampass | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
|
|||||
| CVE-2023-1462 | 1 Vadi | 1 Digikent | 2024-11-21 | N/A | 8.8 HIGH |
|
Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Authentication Bypass, Authentication Abuse. This issue affects DigiKent: before 23.03.20.
|
|||||
| CVE-2023-0985 | 1 Mbconnectline | 2 Mbconnect24, Mymbconnect24 | 2024-11-21 | N/A | 8.8 HIGH |
|
An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to take over the admin user and therefore fully compromise the account.
|
|||||
| CVE-2023-0882 | 2 Krontech, Microsoft | 2 Single Connect, Windows | 2024-11-21 | N/A | 8.8 HIGH |
|
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16.
|
|||||
| CVE-2022-4812 | 1 Usememos | 1 Memos | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
|
|||||
| CVE-2022-4811 | 1 Usememos | 1 Memos | 2024-11-21 | N/A | 8.3 HIGH |
|
Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.
|
|||||
| CVE-2022-4806 | 1 Usememos | 1 Memos | 2024-11-21 | N/A | 5.3 MEDIUM |
|
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
|
|||||
| CVE-2022-4803 | 1 Usememos | 1 Memos | 2024-11-21 | N/A | 8.8 HIGH |
|
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
|
|||||
| CVE-2022-4802 | 1 Usememos | 1 Memos | 2024-11-21 | N/A | 5.4 MEDIUM |
|
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
|
|||||
| CVE-2022-4799 | 1 Usememos | 1 Memos | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
|
|||||
| CVE-2022-4798 | 1 Usememos | 1 Memos | 2024-11-21 | N/A | 5.3 MEDIUM |
|
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
|
|||||
| CVE-2022-4686 | 1 Usememos | 1 Memos | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
|
|||||
| CVE-2022-4505 | 1 Open-emr | 1 Openemr | 2024-11-21 | N/A | 8.8 HIGH |
|
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.
|
|||||
| CVE-2022-46179 | 1 Liuos Project | 1 Liuos | 2024-11-21 | N/A | 9.2 CRITICAL |
|
LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is patched in the latest commit (c658b4f3e57258acf5f6207a90c2f2169698ae22) by requiring the var to be set to true, causing a test script to run instead of being able to login. A potential workaround is to check for the GITHUB_ACT ...
Show More |
|||||
| CVE-2022-43450 | 1 Xwp | 1 Stream | 2024-11-21 | N/A | 4.3 MEDIUM |
|
Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.
|
|||||
| CVE-2022-42175 | 1 Soluslabs | 1 Solusvm | 2024-11-21 | N/A | 8.8 HIGH |
|
Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker to change the password and hostname of other customer servers without authorization.
|
|||||
| CVE-2022-3995 | 1 Standalonetech | 1 Terawallet | 2024-11-21 | N/A | 4.3 MEDIUM |
|
The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to lock/unlock other users wallets.
|
|||||
| CVE-2022-3876 | 1 Clickstudios | 1 Passwordstate | 2024-11-21 | N/A | 4.3 MEDIUM |
|
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown processing of the file /api/browserextension/UpdatePassword/ of the component API. The manipulation of the argument PasswordID leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifie ...
Show More |
|||||
| CVE-2022-3589 | 1 Miele | 1 Appwash | 2024-11-21 | N/A | 8.1 HIGH |
|
An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the API. Reading or changing the password of another user was not possible, thus no impact to Availability.
|
|||||
| CVE-2022-3019 | 1 Tooljet | 1 Tooljet | 2024-11-21 | N/A | 8.8 HIGH |
|
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).
|
|||||
| CVE-2022-39945 | 1 Fortinet | 1 Fortimail | 2024-11-21 | N/A | 5.4 MEDIUM |
|
An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).
|
|||||
| CVE-2022-39018 | 1 M-files | 1 Hubshare | 2024-11-21 | N/A | 8.2 HIGH |
|
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
|
|||||
| CVE-2022-38789 | 1 Airties | 6 Air 4920, Air 4920 Firmware, Air 4921 and 3 more | 2024-11-21 | N/A | 9.1 CRITICAL |
|
An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to arbitrary values, and map the LAN, because of Insecure Direct Object Reference.
|
|||||
| CVE-2022-36539 | 1 Eigen\&wijzer Ouderapp Project | 1 Eigen\&wijzer Ouderapp | 2024-11-21 | N/A | 7.5 HIGH |
|
WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to data of other parents and children.
|
|||||
| CVE-2022-36202 | 1 Doctor\'s Appointment System Project | 1 Doctor\'s Appointment System | 2024-11-21 | N/A | 9.8 CRITICAL |
|
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
|
|||||
| CVE-2022-34775 | 1 Tabit | 1 Tabit | 2024-11-21 | N/A | 6.3 MEDIUM |
|
Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the reservation, and organization. This can be used to query the http://tgm-api.tabit.cloud/rsv/management/{reservationId}?organization={orgId} API which returns a lot of data regarding the reservation (OWASP: API3): Name, mail, phone number, the number of visits of the user to this specific restaurant, the money he spent there, the money he spent on alcoho ...
Show More |
|||||
| CVE-2022-34770 | 1 Tabit | 1 Tabit | 2024-11-21 | N/A | 4.6 MEDIUM |
|
Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bills in a specific restaurant, alcohol consumption and smoking habits. Each of the described API’s, has in its URL one or more MongoDB ID which is not so simple to enumerate. However, they each receive a ‘tiny URL’ in Tabit’s domain, in the form of https://tbit.be/{suffix} with suffix being a 5 characters long string containing number ...
Show More |
|||||
| CVE-2022-34621 | 1 Mealie | 1 Mealie | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modification of the user_id parameter.
|
|||||
| CVE-2022-34150 | 1 Micodus | 2 Mv720, Mv720 Firmware | 2024-11-21 | N/A | 7.1 HIGH |
|
The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on endpoint and parameter device IDs, which accept arbitrary device IDs without further verification.
|
|||||
| CVE-2022-33944 | 1 Micodus | 2 Mv720, Mv720 Firmware | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on endpoint and POST parameter “Device ID,” which accepts arbitrary device IDs.
|
|||||
| CVE-2022-32277 | 1 Squiz | 1 Matrix | 2024-11-21 | N/A | 5.3 MEDIUM |
|
Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contact details. NOTE: this is disputed by both the vendor and the original discoverer because it is a site-specific finding, not a finding about the Squiz Matrix CMS product.
|
|||||
| CVE-2022-31883 | 1 Marvalglobal | 1 Marval Msm | 2024-11-21 | 4.0 MEDIUM | 8.8 HIGH |
|
Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able to see other users API Keys including the Admins API Keys.
|
|||||
| CVE-2022-31131 | 1 Nextcloud | 1 Nextcloud Mail | 2024-11-21 | 4.0 MEDIUM | 5.4 MEDIUM |
|
Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users. It is recommended that the Nextcloud Mail app is upgraded to 1.12.2. There are no known workarounds for this issue. ### Workarounds No workaround available ### References * [Pull request](https://github.com/nextcloud/mail/ ...
Show More |
|||||
| CVE-2022-31027 | 1 Jupyter | 1 Oauthenticator | 2024-11-21 | 4.0 MEDIUM | 4.2 MEDIUM |
|
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuri ...
Show More |
|||||
| CVE-2022-30852 | 1 Withknown | 1 Known | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).
|
|||||
| CVE-2022-30760 | 1 Ihb-eg | 1 Fn2web | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
|
An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authenticated attackers to obtain sensitive student information (final grades, study courses, degrees) by changing the student ID parameter in the HTTP POST request to the FrontControllerSS endpoint.
|
|||||
| CVE-2022-30495 | 1 Automotive Shop Management System Project | 1 Automotive Shop Management System | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
|
In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change the admin password(vertical privilege escalation)
|
|||||