Vulnerabilities (CVE)

Filtered by CWE-639
Total 541 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24834 1 Wisdomgarden 1 Tronclass Ilearn 2023-04-18 N/A 6.5 MEDIUM
WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this vulnerability to access files belonging to other users by modifying the file ID within URL.
CVE-2023-0967 1 Imaworldhealth 1 Bhima 2023-04-17 N/A 6.5 MEDIUM
Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly validate user permissions with respect to certain actions the user can perform.
CVE-2023-26984 1 Peppermint 1 Peppermint 2023-04-05 N/A 8.1 HIGH
An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.
CVE-2023-24842 1 Hgiga 1 Oaklouds Mailsherlock 2023-03-30 N/A 5.3 MEDIUM
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.
CVE-2021-36400 1 Moodle 1 Moodle 2023-03-13 N/A 5.3 MEDIUM
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
CVE-2023-25403 1 Yf-exam Project 1 Yf-exam 2023-03-10 N/A 7.5 HIGH
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged with his username to bypass authentication.
CVE-2019-14246 1 Centos-webpanel 1 Centos Web Panel 2023-03-03 4.0 MEDIUM 6.5 MEDIUM
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.
CVE-2019-14245 1 Centos-webpanel 1 Centos Web Panel 2023-03-03 5.5 MEDIUM 6.5 MEDIUM
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.
CVE-2022-4812 1 Usememos 1 Memos 2023-03-02 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4806 1 Usememos 1 Memos 2023-03-02 N/A 5.3 MEDIUM
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4803 1 Usememos 1 Memos 2023-03-02 N/A 8.8 HIGH
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4799 1 Usememos 1 Memos 2023-03-02 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4802 1 Usememos 1 Memos 2023-03-02 N/A 5.4 MEDIUM
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4798 1 Usememos 1 Memos 2023-03-02 N/A 5.3 MEDIUM
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2019-12252 1 Zohocorp 1 Manageengine Servicedesk Plus 2023-03-01 4.0 MEDIUM 6.5 MEDIUM
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.
CVE-2022-0691 1 Url-parse Project 1 Url-parse 2023-02-23 7.5 HIGH 9.8 CRITICAL
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
CVE-2022-0686 1 Url-parse Project 1 Url-parse 2023-02-23 6.4 MEDIUM 9.1 CRITICAL
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
CVE-2022-0639 1 Url-parse Project 1 Url-parse 2023-02-23 5.0 MEDIUM 5.3 MEDIUM
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
CVE-2022-0512 1 Url-parse Project 1 Url-parse 2023-02-23 5.0 MEDIUM 5.3 MEDIUM
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
CVE-2023-25160 1 Nextcloud 1 Mail 2023-02-22 N/A 5.3 MEDIUM
Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25, Mail 1.14.5 for Nextcloud 22-24, Mail 1.12.9 for Nextcloud 21, or Mail 1.11.8 for Nextcloud 20 to receive a patch. No known workarounds are available.