Filtered by vendor
Subscriptions
Total
718 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-37630 | 1 Nextcloud | 1 Circles | 2024-11-21 | 6.5 Medium |
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed any user to join any "Secret Circle" without approval by the Circle owner leaking private information. It is recommended that Nextcloud Circles is upgraded to 0.19.15, 0.20.11 or 0.21.4. There are no workarounds for this issue. | ||||
CVE-2021-37628 | 1 Nextcloud | 1 Richdocuments | 2024-11-21 | 7.5 High |
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able to read arbitrary files in such a share. It is recommended that the Nextcloud Richdocuments is upgraded to 3.8.4 or 4.2.1. If upgrading is not possible then it is recommended to disable the Richdocuments application. | ||||
CVE-2021-37331 | 1 Bookingcore | 1 Booking Core | 2024-11-21 | 5.3 Medium |
Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards and Trade Licenses of other vendors/users can be viewed by changing the URL. | ||||
CVE-2021-37215 | 1 Larvata | 1 Flygo | 2024-11-21 | 4.3 Medium |
The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attacker can manipulate the user data and then over-write another employee’s user data by specifying that employee’s ID in the API parameter. | ||||
CVE-2021-37214 | 1 Larvata | 1 Flygo | 2024-11-21 | 8.8 High |
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command. | ||||
CVE-2021-37213 | 1 Larvata | 1 Flygo | 2024-11-21 | 4.3 Medium |
The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID and date in specific parameters to access particular employee’s check-in record. | ||||
CVE-2021-37212 | 1 Larvata | 1 Flygo | 2024-11-21 | 5.4 Medium |
The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the bulletin ID in specific Url parameters and access and modify bulletin particular content. | ||||
CVE-2021-37184 | 1 Siemens | 1 Industrial Edge Management | 2024-11-21 | 9.8 Critical |
A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker could change the the password of any user in the system under certain circumstances. With this an attacker could impersonate any valid user on an affected system. | ||||
CVE-2021-36906 | 1 Expresstech | 1 Quiz And Survey Master | 2024-11-21 | 2.7 Low |
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 on WordPress. | ||||
CVE-2021-36874 | 1 Stylemixthemes | 1 Ulisting | 2024-11-21 | 7.1 High |
Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5). | ||||
CVE-2021-36865 | 1 Quizandsurveymaster | 1 Quiz And Survey Master | 2024-11-21 | 3.8 Low |
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPress allows attackers to change the content of the quiz. | ||||
CVE-2021-36801 | 1 Akaunting | 1 Akaunting | 2024-11-21 | 8.1 High |
Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product. | ||||
CVE-2021-36539 | 1 Instructure | 1 Canvas Learning Management Service | 2024-11-21 | 6.5 Medium |
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url). | ||||
CVE-2021-36400 | 1 Moodle | 1 Moodle | 2024-11-21 | 5.3 Medium |
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. | ||||
CVE-2021-36389 | 1 Yellowfinbi | 1 Yellowfin | 2024-11-21 | 7.5 High |
In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4". | ||||
CVE-2021-36388 | 1 Yellowfinbi | 1 Yellowfin | 2024-11-21 | 7.5 High |
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIIAvatarImage.i4". | ||||
CVE-2021-36387 | 1 Yellowfinbi | 1 Yellowfin | 2024-11-21 | 5.4 Medium |
In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4". | ||||
CVE-2021-36329 | 1 Dell | 1 Emc Streaming Data Platform | 2024-11-21 | 6.5 Medium |
Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information. | ||||
CVE-2021-36032 | 1 Adobe | 2 Adobe Commerce, Magento Open Source | 2024-11-21 | 8.3 High |
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability. An authenticated attacker can trigger an insecure direct object reference in the `V1/customers/me` endpoint to achieve information exposure and privilege escalation. | ||||
CVE-2021-35337 | 1 Phone Shop Sales Management System Project | 1 Phone Shop Sales Management System | 2024-11-21 | 4.3 Medium |
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter. |