Skip to main content

CWE archive

CWE-639 CVEs

Programmatic archive

2,270 CVEs tagged with CWE-639173 Critical, 711 High, 1,226 Medium, 158 Low, 2 Unrated.

CVE-2022-2828

Published Oct 13, 2022

In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1613

Published Sep 26, 2022

The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40186

Published Sep 22, 2022

An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-1580

Published Sep 19, 2022

The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2877

Published Sep 16, 2022

The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it'…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32277

Published Sep 6, 2022

Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's conta…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2080

Published Aug 29, 2022

The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2034

Published Aug 29, 2022

The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing unauthenticated users to access private messages sent to te…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3019

Published Aug 29, 2022

The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an optio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-4142

Published Aug 24, 2022

The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34775

Published Aug 22, 2022

Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containing the MongoDB ID of the reservation, and organization. Thi…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34770

Published Aug 22, 2022

Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive information such as health statements, previous bills in a speci…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2198

Published Aug 22, 2022

The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying private messages, allowing any lo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34621

Published Aug 19, 2022

Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modif…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2824

Published Aug 15, 2022

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2535

Published Aug 15, 2022

The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited to published posts only, allowing unauthenticated users to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2730

Published Aug 9, 2022

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2367

Published Aug 8, 2022

The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" paramete…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36284

Published Aug 5, 2022

Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Paym…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,976-2,000 of 2,270 CVEsPage 80 of 91