CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,573 vulnerabilities with CWE-639
CVE-2025-13389
MEDIUM
WooCommerce: OrderConvo <14 - Info Disclosure
CVSS 5.3
CVE-2025-13382
MEDIUM
Frontend File Manager Plugin <23.4 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-12040
MEDIUM
WooCommerce Wishlist <1.0.9 - Insecure Direct Object Reference
CVSS 6.5
CVE-2025-10039
MEDIUM
Elula Wsdesk < 3.3.0 - IDOR
CVSS 4.3
CVE-2025-12881
MEDIUM
WooCommerce <4.5.5 - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-12086
MEDIUM
Return Refund & Exchange For WooCommerce <4.5.5 - Insecure Direct O...
CVSS 4.3
CVE-2025-52670
MEDIUM
Revive-adserver Revive Adserver < 5.5.2 - Missing Authorization
CVSS 6.5
CVE-2025-65034
HIGH
Rallly < 4.5.4 - IDOR
CVSS 8.1
CVE-2025-65033
HIGH
Rallly < 4.5.4 - Improper Authorization
CVSS 8.1
CVE-2025-65032
MEDIUM
Rallly < 4.5.4 - IDOR
CVSS 6.5
CVE-2025-65031
MEDIUM
Rallly < 4.5.4 - Improper Authorization
CVSS 6.5
CVE-2025-65030
HIGH
Rallly < 4.5.4 - Improper Authorization
CVSS 7.1
CVE-2025-65029
HIGH
Rallly < 4.5.4 - Missing Authorization
CVSS 8.1
CVE-2025-65028
MEDIUM
Rallly < 4.5.4 - Missing Authorization
CVSS 6.5
CVE-2025-65021
CRITICAL
Rallly < 4.5.4 - Missing Authorization
CVSS 9.1
CVE-2025-65020
MEDIUM
Rallly < 4.5.4 - Missing Authorization
CVSS 6.5
CVE-2025-12766
MEDIUM
BlackBerry AtHoc OnPrem <7.21 - Info Disclosure
CVSS 5.0
CVE-2025-12427
MEDIUM
YITH WooCommerce Wishlist <4.10.0 - Info Disclosure
CVSS 5.3
CVE-2025-63513
MEDIUM
kishan0725 Hospital Management System v4 - Info Disclosure
CVSS 6.5
CVE-2025-12524
MEDIUM
Post Type Switcher <4.0.0 - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-63291
MEDIUM
Alteryx Server 2022.1.1.42654-2024.1 - Info Disclosure
CVSS 5.4
CVE-2025-8855
HIGH
Optimus Software Brokerage Automation <1.1.71 - Auth Bypass
CVSS 8.1
CVE-2025-64706
MEDIUM
Typebot < 3.13.0 - Improper Access Control
CVSS 5.0
CVE-2025-41069
MEDIUM
T-INNOVA DeporSite - IDOR
CVE-2025-12366
MEDIUM
Pagelayer <2.0.5 - Insecure Direct Object Reference
CVSS 4.3
Details
Vulnerabilities
1,573
Exploit Likelihood
High