Skip to main content

CWE archive

CWE-639 CVEs

Programmatic archive

2,270 CVEs tagged with CWE-639173 Critical, 711 High, 1,226 Medium, 158 Low, 2 Unrated.

CVE-2022-24979

Published Feb 19, 2022

An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content element renderer component does not include an access check. Thi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25336

Published Feb 18, 2022

Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows Insecure Direct Object Reference (IDOR) attacks against image files because the image path…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46249

Published Feb 15, 2022

An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25096

Published Feb 7, 2022

The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22832

Published Feb 6, 2022

An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-41608

Published Jan 28, 2022

A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user su…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22828

Published Jan 27, 2022

An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded fil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23856

Published Jan 24, 2022

An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotp…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44836

Published Jan 18, 2022

An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it is possible for an unprivileged user to reopen a risk with a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3852

Published Jan 12, 2022

growi is vulnerable to Authorization Bypass Through User-Controlled Key

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24739

Published Dec 21, 2021

The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel D…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43828

Published Dec 14, 2021

PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManage…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43820

Published Dec 14, 2021

Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cac…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 2,051-2,075 of 2,270 CVEsPage 83 of 91