CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,573 vulnerabilities with CWE-639
CVE-2025-6038 HIGH
Lisfinity Core - Privilege Escalation
CVSS 8.8
CVE-2025-43724 MEDIUM
Dell Powerscale Onefs < 9.5.1.5 - IDOR
CVSS 4.4
CVE-2025-40676 MEDIUM
Negotiator v3.15.2 - IDOR
CVE-2025-0606 MEDIUM
Logo Cloud <0.67 - Auth Bypass
CVSS 6.0
CVE-2025-11321 MEDIUM
zhuimengshaonian wisdom-education <1.0.4 - Auth Bypass
CVSS 4.3
CVE-2025-0642 MEDIUM
PosCube Hardware Software and Consulting Ltd. Co. Assist <10.02.202...
CVSS 6.3
CVE-2025-58055 MEDIUM
Discourse < 3.5.1 - Improper Access Control
CVSS 4.3
CVE-2025-59687 MEDIUM
IMPAQTR Aurora <1.36 - Info Disclosure
CVSS 4.3
CVE-2025-56392 HIGH
Syauqi Collegetivity - IDOR
CVSS 8.1
CVE-2025-43827 MEDIUM
Liferay Digital Experience Platform < 7.3 - IDOR
CVSS 4.3
CVE-2025-41099 MEDIUM
Boldworkplanner Bold Workplanner < 2.5.25 - IDOR
CVSS 6.5
CVE-2025-41098 HIGH
Boldworkplanner Bold Workplanner < 2.5.25 - IDOR
CVSS 7.5
CVE-2025-41097 MEDIUM
Boldworkplanner Bold Workplanner < 2.5.25 - IDOR
CVSS 4.3
CVE-2025-41096 MEDIUM
Boldworkplanner Bold Workplanner < 2.5.25 - IDOR
CVSS 4.3
CVE-2025-41095 MEDIUM
Boldworkplanner Bold Workplanner < 2.5.25 - IDOR
CVSS 4.3
CVE-2025-41094 MEDIUM
Boldworkplanner Bold Workplanner < 2.5.25 - IDOR
CVSS 4.3
CVE-2025-41093 MEDIUM
Boldworkplanner Bold Workplanner < 2.5.25 - IDOR
CVSS 4.3
CVE-2025-41092 MEDIUM
Boldworkplanner Bold Workplanner < 2.5.25 - IDOR
CVSS 4.3
CVE-2025-41091 MEDIUM
Boldworkplanner Bold Workplanner < 2.5.25 - IDOR
CVSS 4.3
CVE-2025-55795 LOW
openml/openml.org v2.0.20241110 - Open Redirect
CVSS 3.5
CVE-2025-10947 MEDIUM
Sistemas Pleno Gestão de Locação <2025.7.x - Auth Bypass
CVSS 5.3
CVE-2025-9342 MEDIUM
AHE Mobile <1.9.9 - Auth Bypass
CVSS 6.5
CVE-2025-7106 MEDIUM
Librechat < 0.7.9 - Improper Access Control
CVSS 5.3
CVE-2025-43810 MEDIUM
Liferay Digital Experience Platform < 2023.Q3.10 - IDOR
CVSS 4.3
CVE-2025-59562 MEDIUM
Academy LMS <3.3.4 - Auth Bypass
CVSS 5.5
Details
Vulnerabilities 1,573
Exploit Likelihood High