CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,572 vulnerabilities with CWE-639
CVE-2025-65887
MEDIUM
OneFlow <0.9.0 - DoS
CVSS 6.5
CVE-2025-9520
MEDIUM
Omada Controllers - SSRF
CVSS 6.8
CVE-2025-14459
HIGH
KubeVirt CDI - Privilege Escalation
CVSS 8.5
CVE-2025-47555
LOW
Themeum Tutor LMS <3.9.4 - Auth Bypass
CVSS 3.8
CVE-2025-65098
HIGH
Typebot < 3.13.2 - Missing Authorization
CVSS 7.4
CVE-2025-10855
HIGH
Teknoera <01102025 - Auth Bypass
CVSS 7.5
CVE-2025-10024
HIGH
EXERT Computer Technologies Software Ltd. Co. Education Management ...
CVSS 7.5
CVE-2025-15521
CRITICAL
Academy LMS - WordPress LMS Plugin <3.5.0 - Privilege Escalation
CVSS 9.8
CVE-2025-14844
HIGH
Liquidweb Restrict Content < 3.2.17 - IDOR
CVSS 8.2
CVE-2025-15370
MEDIUM
Shield: Blocks Bots - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-64516
HIGH
Glpi < 10.0.21 - Improper Access Control
CVSS 7.5
CVE-2025-68492
MEDIUM
Pypi Chainlit < 2.8.5 - IDOR
CVSS 4.2
CVE-2025-40805
CRITICAL
Siemens Industrial Edge Cloud Device and Device Kit - Authentication Bypass
CVSS 10.0
CVE-2025-41077
HIGH
Viafirma Inbox < 4.5.27 - IDOR
CVSS 8.1
CVE-2025-69274
HIGH
Broadcom DX Netops Spectrum < 24.3.11 - IDOR
CVSS 8.8
CVE-2025-13457
HIGH
WooCommerce Square <5.1.1 - Info Disclosure
CVSS 7.5
CVE-2025-4596
MEDIUM
Asseco ADMX <6.09.01.62 - Info Disclosure
CVE-2025-67919
MEDIUM
WofficeIO Woffice Core <5.4.30 - Auth Bypass
CVSS 6.5
CVE-2025-15018
CRITICAL
WordPress Optional Email <1.3.11 - Privilege Escalation
CVSS 9.8
CVE-2025-14802
MEDIUM
LearnPress - WordPress LMS Plugin <4.3.2.2 - Info Disclosure
CVSS 5.4
CVE-2025-12030
MEDIUM
ACF to REST API <3.3.4 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-15001
CRITICAL
FS Registration Password <1.0.1 - Privilege Escalation
CVSS 9.8
CVE-2025-14996
CRITICAL
WordPress Default Registration Form <2.0.0 - Privilege Escalation
CVSS 9.8
CVE-2025-68044
HIGH
Rustaurius Five Star Restaurant Reservations <2.7.9 - Auth Bypass
CVSS 8.6
CVE-2025-14998
CRITICAL
Branda WordPress <3.4.24 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities
1,572
Exploit Likelihood
High