VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

670 CVEsRSS

CVE-2024-11146Medium· 6.3
1y ago

TrueFiling authorization bypass via user-controlled keys

TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling is an entirely cloud-hosted application.…

▾ Sunliti3 Verticals · TrueFilingEPSS 0.33%via CVEORG
CVE-2024-33668Critical· 9.1PoC
2y ago

An issue was discovered in Zammad before 6.3.0

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no …

▾ Abyssalzammad · zammadEPSS 0.45%via NVD
CVE-2024-1313Medium· 6.5
2y ago

grafana: vulnerable to authorization bypass (CVE-2024-1313)

A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2023-43900Medium· 6.5
2y ago

Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.

Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.

▾ Sunlitemudhra · emsignerEPSS 0.59%via NVD
CVE-2022-36202Critical· 9.8
4y ago

Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php

Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.

▾ Midnightdoctor's_appointment_system_project · doctor's_appointment_systemEPSS 0.89%via NVD
CVE-2022-28986High· 7.5PoC
4y ago

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone n…

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone n…

▾ Midnightlmsdoctor · 2_factor_authenticationEPSS 2.3%via NVD
CVE-2021-46416High· 8.1PoC
4y ago

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

▾ Midnightsma · sunny_tripower_firmwareEPSS 4.3%via NVD
CVE-2021-3380Medium· 6.5
4y ago

Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print Invoice Functionality.

Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print Invoice Functionality.

▾ Sunlitheight8tech · h8_ssrmsEPSS 1.1%via NVD
CVE-2020-26679Medium· 4.3
5y ago

vFairs 3.3 is affected by Insecure Permissions

vFairs 3.3 is affected by Insecure Permissions. Any user logged in to a vFairs virtual conference or event can modify any other users profile information or profile picture. After receiving any user's unique identification number and the…

▾ Sunlitvfairs · vfairsEPSS 0.77%via NVD
CVE-2020-23446Medium· 5.3
6y ago

Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API

Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API

▾ Sunlitverint · workforce_optimizationEPSS 1.2%via NVD
CWE-639 vulnerabilities (CVEs) — page 23 · VulnSea