CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,573 vulnerabilities with CWE-639
CVE-2025-0670 MEDIUM
Akinsoft ProKuafor <1.02.08 - Auth Bypass
CVSS 4.7
CVE-2025-56254 MEDIUM
Phpgurukul Employee Leave Management System - IDOR
CVSS 4.3
CVE-2025-0640 MEDIUM
Akinsoft OctoCloud <1.11.01 - Auth Bypass
CVSS 4.7
CVE-2025-8447 LOW
Github Enterprise Server < 3.14.17 - IDOR
CVSS 3.1
CVE-2025-45968 CRITICAL
System Pdv - IDOR
CVSS 9.8
CVE-2025-55621 MEDIUM
Reolink v4.54.0.4.20250526 - IDOR
CVSS 6.5
CVE-2025-57886 MEDIUM
Equalize Digital Accessibility Checker <1.30.0 - Auth Bypass
CVSS 5.4
CVE-2025-55370 HIGH
jshERP <3.5 - Info Disclosure
CVSS 8.8
CVE-2025-9264 MEDIUM
Xuxueli xxl-job <3.1.1 - Info Disclosure
CVSS 5.4
CVE-2025-9263 MEDIUM
Xuxueli xxl-job <3.1.1 - Info Disclosure
CVSS 4.3
CVE-2025-5261 HIGH
Pik Online <3.1.5 - Auth Bypass
CVSS 7.5
CVE-2025-53208 HIGH
Maya Business <1.2.0 - Auth Bypass
CVSS 7.5
CVE-2025-55737 MEDIUM
flaskBlog <2.8.0 - Info Disclosure
CVSS 6.5
CVE-2025-43732 LOW
Liferay Digital Experience Platform < 2024.Q1.18 - IDOR
CVSS 2.7
CVE-2025-54691 MEDIUM
Stylemix Motors <1.4.80 - Auth Bypass
CVSS 5.3
CVE-2025-8770 MEDIUM
Gitlab < 18.0.6 - IDOR
CVSS 6.5
CVE-2025-3089 MEDIUM
ServiceNow AI Platform - Privilege Escalation
CVE-2025-8794 MEDIUM
Litmus < 3.19.0 - Improper Authorization
CVSS 5.3
CVE-2025-8789 MEDIUM
Portabilis I-educar < 2.9.0 - Improper Authorization
CVSS 4.3
CVE-2025-8755 MEDIUM
Macrozheng Mall < 1.0.3 - Improper Authorization
CVSS 5.3
CVE-2025-4796 HIGH
Themewinter Eventin < 4.0.35 - IDOR
CVSS 8.8
CVE-2025-36023 MEDIUM
IBM Cloud Pak For Business Automation - IDOR
CVSS 6.5
CVE-2025-51533 MEDIUM
Sagedpw Sage Dpw < 2025_06_000 - IDOR
CVSS 5.3
CVE-2025-46387 HIGH
Unknown Product - Auth Bypass
CVSS 8.8
CVE-2025-46386 HIGH
Emby MediaBrowser 4.9.0.35 - Authorization Bypass Through User-Controlled Key
CVSS 8.8
Details
Vulnerabilities 1,573
Exploit Likelihood High