Skip to main content

CWE archive

CWE-639 CVEs

Programmatic archive

2,270 CVEs tagged with CWE-639173 Critical, 711 High, 1,226 Medium, 158 Low, 2 Unrated.

CVE-2022-29159

Published May 20, 2022

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1425

Published May 16, 2022

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax actio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27247

Published May 13, 2022

onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any customer (e.g., data of birth, full address, mail informati…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1352

Published May 11, 2022

Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1, an end…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29008

Published May 11, 2022

An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28986

Published May 10, 2022

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to up…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23061

Published May 1, 2022

In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen according to the documentation) via Insecure Direct Object Refe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24800

Published Apr 25, 2022

The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user making the request, allowing any user to edit other comment…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1461

Published Apr 25, 2022

Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26665

Published Apr 18, 2022

An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29287

Published Apr 16, 2022

Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user management rights (default is Administrator) to export the user o…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27108

Published Apr 6, 2022

OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/createTimesheet`. Any user can create a timesheet in another u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1165

Published Apr 4, 2022

The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, wh…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-22331

Published Apr 1, 2022

IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38362

Published Mar 30, 2022

In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint that is vulnerable to an Insecure Direct Object Reference (IDO…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26254

Published Mar 27, 2022

WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID na…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43957

Published Mar 16, 2022

Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF direc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0442

Published Mar 7, 2022

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logge…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25471

Published Mar 3, 2022

An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41111

Published Feb 28, 2022

Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.5 and 3.3.15, an authenticated user with authorization to r…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,026-2,050 of 2,270 CVEsPage 82 of 91