CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,572 vulnerabilities with CWE-639
CVE-2026-22396
MEDIUM
Mikado-Themes Fiorello <=1.0 - Auth Bypass
CVSS 5.4
CVE-2026-22393
MEDIUM
Mikado-Themes Curly <3.3 - Auth Bypass
CVSS 5.4
CVE-2026-22391
MEDIUM
Mikado-Themes Cocco <1.5.2 - Auth Bypass
CVSS 5.4
CVE-2026-23964
MEDIUM
Mastodon <4.5.5-4.3.18 - Info Disclosure
CVSS 6.5
CVE-2026-23754
HIGH
D-Link D-View 8 <2.0.1.107 - Privilege Escalation
CVSS 8.8
CVE-2026-23844
MEDIUM
Whisper Money <0.1.5 - Info Disclosure
CVSS 4.3
CVE-2026-23843
HIGH
teklifolustur_app - IDOR
CVSS 7.1
CVE-2026-23522
LOW
LobeChat <2.0.0-next.193 - Privilege Escalation
CVSS 3.7
CVE-2026-23478
CRITICAL
Cal.com <6.0.7 - Auth Bypass
CVSS 9.8
CVE-2026-22050
MEDIUM
Netapp Ontap - IDOR
CVSS 4.3
CVE-2026-22589
HIGH
Spree < 4.10.2 - IDOR
CVSS 7.5
CVE-2026-21409
MEDIUM
RICOH Streamline NX 3.5.1-24R3 - Info Disclosure
CVSS 5.9
CVE-2026-22588
MEDIUM
Spree < 4.10.2 - IDOR
CVSS 6.5
CVE-2026-22235
HIGH
OPEXUS eComplaint <9.0.45.0 - Info Disclosure
CVSS 7.5
CVE-2026-22234
CRITICAL
OPEXUS eCasePortal <9.0.45.0 - Info Disclosure
CVSS 9.8
CVE-2026-22489
MEDIUM
Wptexture Image Slider Slideshow <1.8 - Auth Bypass
CVSS 4.3
CVE-2026-21447
HIGH
Webkul Bagisto < 2.3.10 - Improper Access Control
CVSS 7.1
CVE-2025-15626
MEDIUM
Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application
CVE-2025-66286
MEDIUM
Webkitgtk: authorization bypass through webpage::send-request signal handler
CVSS 4.7
CVE-2025-66954
MEDIUM
Buffalo Link Station 1.85-0.01 - Info Disclosure
CVSS 6.5
CVE-2025-13822
MEDIUM
Authentication bypass in MCPHub
CVE-2025-14974
MEDIUM
IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference
CVSS 5.7
CVE-2025-69347
HIGH
WordPress WPSubscription plugin <= 1.8.10 - Insecure Direct Object References (IDOR) vulnerability
CVSS 8.6
CVE-2025-32223
MEDIUM
WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2025-69727
MEDIUM
INDEX-EDUCATION PRONOTE <2025.2.8 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
1,572
Exploit Likelihood
High