CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,573 vulnerabilities with CWE-639
CVE-2025-34293
HIGH
GN4 Publishing System <2.6 - Info Disclosure
CVE-2025-11957
HIGH
Devolutions Server < 2025.2.14.0 - IDOR
CVSS 8.4
CVE-2025-49952
MEDIUM
Houzez <4.1.1 - Auth Bypass
CVSS 6.5
CVE-2025-6833
MEDIUM
All in One Time Clock Lite - WordPress <2.0 - Insecure Direct Objec...
CVSS 4.3
CVE-2025-10570
MEDIUM
WooCommerce Flexible Refund Return Order <1.0.38 - Auth Bypass
CVSS 4.3
CVE-2025-60511
MEDIUM
Moodle OpenAI Chat Block plugin 3.0.1 - IDOR
CVSS 4.3
CVE-2025-8884
MEDIUM
VHS Electronic Software Ltd. Co. ACE Center <3.10.161.2255 - Privil...
CVSS 5.5
CVE-2025-11741
MEDIUM
WPC Smart Quick View <4.2.5 - Info Disclosure
CVSS 5.3
CVE-2025-11519
MEDIUM
Optimole <4.1.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-11517
HIGH
WordPress Event Tickets & Registration <5.26.5 - Auth Bypass
CVSS 7.5
CVE-2025-11895
MEDIUM
Binary MLM Plan <3.0 - Info Disclosure
CVSS 4.3
CVE-2025-9559
MEDIUM
Pega Platform <Infinity - Info Disclosure
CVSS 6.5
CVE-2025-41020
HIGH
Sergestec Exito - IDOR
CVSS 7.5
CVE-2025-10742
CRITICAL
Truelysell Core <1.8.6 - Privilege Escalation
CVSS 9.8
CVE-2025-11176
MEDIUM
Quick Featured Images <13.7.2 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-40773
LOW
Siemens Sipass Integrated < 3.00 - IDOR
CVSS 3.5
CVE-2025-62252
MEDIUM
Liferay Digital Experience Platform < 7.4 - IDOR
CVSS 4.3
CVE-2025-62242
MEDIUM
Liferay Digital Experience Platform < 7.4.3.112 - IDOR
CVSS 4.3
CVE-2025-62241
MEDIUM
Liferay Digital Experience Platform < 4.0.114 - IDOR
CVSS 4.3
CVE-2025-62244
MEDIUM
Liferay Digital Experience Platform < 2023.q3.9 - IDOR
CVSS 4.3
CVE-2025-9902
HIGH
AKIN Software Computer Import Export Industry and Trade Co. Ltd. QR...
CVSS 7.5
CVE-2025-31997
MEDIUM
Hcltech Unica Centralized Offer Management < 25.1.0.1 - IDOR
CVSS 4.2
CVE-2025-11518
MEDIUM
WPC Smart Wishlist <5.0.3 - Insecure Direct Object Reference
CVSS 5.3
CVE-2025-8887
MEDIUM
Usta Information Systems Inc. Aybs Interaktif - Info Disclosure
CVSS 6.1
CVE-2025-61779
HIGH
Confidential Containers Trustee <0.15.0 - Auth Bypass
Details
Vulnerabilities
1,573
Exploit Likelihood
High