Skip to main content

CWE archive

CWE-639 CVEs

Programmatic archive

2,270 CVEs tagged with CWE-639173 Critical, 711 High, 1,226 Medium, 158 Low, 2 Unrated.

CVE-2022-3876

Published Dec 19, 2022

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown pro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4505

Published Dec 15, 2022

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4097

Published Dec 12, 2022

The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to bypassed security features (like IP blocks, rate limiting, br…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38765

Published Dec 9, 2022

Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2808

Published Dec 2, 2022

Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection. This issue affects P…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3995

Published Nov 29, 2022

The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24187

Published Nov 28, 2022

The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. Other end-users user_id and dev…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3589

Published Nov 21, 2022

An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43492

Published Nov 18, 2022

Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44005

Published Nov 16, 2022

An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the newsletter sign-up functionality is vulnerable to the enumer…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3413

Published Nov 10, 2022

Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allowed Devel…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40206

Published Nov 8, 2022

Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum pos…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40205

Published Nov 8, 2022

Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum pos…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39945

Published Nov 2, 2022

An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin u…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39018

Published Oct 31, 2022

Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36966

Published Oct 20, 2022

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33077

Published Oct 19, 2022

An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the addressedit endpoint.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41479

Published Oct 18, 2022

The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3331

Published Oct 17, 2022

An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 b…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1,951-1,975 of 2,270 CVEsPage 79 of 91