Total
2039 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-3288 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 8.5 HIGH |
| A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation. | |||||
| CVE-2023-3287 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 9.9 CRITICAL |
| A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege escalation. | |||||
| CVE-2023-3286 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 7.7 HIGH |
| A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation. | |||||
| CVE-2023-3285 | 2026-06-17 | N/A | 7.7 HIGH | ||
| A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the system (including admin). This results in unauthorized data manipulation. | |||||
| CVE-2023-3105 | 1 Learndash | 1 Learndash | 2026-06-17 | N/A | 8.8 HIGH |
| The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with existing account access at any level, to change user passwords and potentially take over administrator accounts. | |||||
| CVE-2023-3066 | 1 Mobatime | 1 Amxgt 100 | 2026-06-17 | N/A | 8.1 HIGH |
| Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonate anyone else, including administratorsThis issue affects Mobatime mobile application AMXGT100: through 1.3.20. | |||||
| CVE-2023-3063 | 1 Smartypantsplugins | 1 Sp Project \& Document Manager | 2026-06-17 | N/A | 8.8 HIGH |
| The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber privileges or above, to change user passwords and potentially take over administrator accounts. | |||||
| CVE-2023-3048 | 1 Tmtmakine | 2 Lockcell, Lockcell Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass. This issue affects Lockcell: before 15. | |||||
| CVE-2023-38965 | 1 Oretnom23 | 1 Lost And Found Information System | 2026-06-17 | N/A | 9.8 CRITICAL |
| Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI. | |||||
| CVE-2023-38884 | 1 Os4ed | 1 Opensis | 2026-06-17 | N/A | 7.5 HIGH |
| An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>' | |||||
| CVE-2023-38872 | 1 Economizzer | 1 Economizzer | 2026-06-17 | N/A | 3.7 LOW |
| An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment. | |||||
| CVE-2023-38513 | 1 Meowapps | 1 Photo Engine | 2026-06-17 | N/A | 5.4 MEDIUM |
| Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engine (Media Organizer & Lightroom): from n/a through 6.2.5. | |||||
| CVE-2023-38055 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 9.6 CRITICAL |
| A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |||||
| CVE-2023-38054 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 9.9 CRITICAL |
| A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data manipulation. | |||||
| CVE-2023-38053 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 9.9 CRITICAL |
| A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |||||
| CVE-2023-38052 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 9.9 CRITICAL |
| A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation. | |||||
| CVE-2023-38051 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 9.9 CRITICAL |
| A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation. | |||||
| CVE-2023-38050 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 9.1 CRITICAL |
| A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |||||
| CVE-2023-38049 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 9.9 CRITICAL |
| A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipulation. | |||||
| CVE-2023-38048 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 9.9 CRITICAL |
| A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in unauthorized access and unauthorized data manipulation. | |||||
