CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,573 vulnerabilities with CWE-639
CVE-2025-64523
HIGH
Filebrowser < 2.45.1 - Improper Authorization
CVSS 8.8
CVE-2025-12903
HIGH
Braintree For WooCommerce <3.2.78 - Auth Bypass
CVSS 7.5
CVE-2025-12833
MEDIUM
GeoDirectory - WP Business Directory Plugin <2.8.139 - Insecure Dir...
CVSS 4.3
CVE-2025-12087
MEDIUM
Woocommerce plugin <1.1.22 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-12126
MEDIUM
The Total Book Project plugin - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-11532
MEDIUM
Wisly plugin - Insecure Direct Object Reference
CVSS 5.3
CVE-2025-12919
LOW
EverShop <2.0.1 - Info Disclosure
CVSS 3.7
CVE-2025-12918
LOW
yungifez Skuul School Management System <2.6.5 - Info Disclosure
CVSS 3.1
CVE-2025-12353
MEDIUM
WPFunnels <3.6.2 - Unauthorized Registration
CVSS 5.3
CVE-2025-11748
MEDIUM
Groups plugin for WordPress <3.7.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-64431
HIGH
Zitadel < 4.6.3 - IDOR
CVE-2025-12854
LOW
newbee-mall-plus <2.4.1 - Auth Bypass
CVSS 3.7
CVE-2025-58627
CRITICAL
Miraculous Core Plugin < 2.0.9 - Auth Bypass
CVSS 9.8
CVE-2025-63248
HIGH
DWSurvey 6.14.0 - Privilege Escalation
CVSS 7.5
CVE-2025-11690
HIGH
VehicleId IDOR - Info Disclosure
CVSS 8.5
CVE-2025-0987
CRITICAL
CB Project Ltd. Co. CVLand <20251103 - Auth Bypass
CVSS 9.9
CVE-2025-12623
LOW
fushengqian fuint <41e26be8a2c609413a0feaa69bdad33a71ae8032 - Auth ...
CVSS 3.1
CVE-2025-6574
HIGH
Service Finder Bookings <6.1 - Privilege Escalation
CVSS 8.8
CVE-2025-5949
HIGH
Service Finder Bookings <6.0 - Privilege Escalation
CVSS 8.8
CVE-2025-61876
MEDIUM
Inforcer Platform <2.0.153 - Info Disclosure
CVSS 5.0
CVE-2025-64283
MEDIUM
Rometheme RTMKit <1.6.7 - Auth Bypass
CVSS 6.5
CVE-2025-12351
MEDIUM
Honeywell S35 Series Cameras - Privilege Escalation
CVSS 6.8
CVE-2025-12288
MEDIUM
Bdtask Pharmacare < 9.4 - Improper Authorization
CVSS 4.3
CVE-2025-12283
MEDIUM
Fabian Client Details System - Improper Authorization
CVSS 4.3
CVE-2025-12270
MEDIUM
LearnHouse <98dfad76aad70711a8113f6c1fdabfccf10509ca - Info Disclosure
CVSS 4.3
Details
Vulnerabilities
1,573
Exploit Likelihood
High