CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,573 vulnerabilities with CWE-639
CVE-2025-4855 CRITICAL
Schiocco Support Board < 3.8.1 - IDOR
CVSS 9.8
CVE-2025-6942 LOW
Secret Server <11.7.49 - Privilege Escalation
CVSS 3.8
CVE-2025-6765 MEDIUM
Intelbras Incontrol Web - IDOR
CVSS 6.3
CVE-2025-49135 MEDIUM
Cvat Computer Vision Annotation Tool < 2.40.0 - IDOR
CVSS 6.5
CVE-2025-50693 MEDIUM
PHPGurukul Online DJ Booking Management System 2.0 - IDOR
CVSS 6.5
CVE-2025-3091 HIGH
Helmholz myREX24 and MB connect line mbCONNECT24/mymbCONNECT24 - Authentication Bypass
CVSS 7.5
CVE-2025-6534 MEDIUM
xxyopen/201206030 novel-plus <5.1.3 - Improper Control of Resource ...
CVSS 4.2
CVE-2025-49995 MEDIUM
dFactory Download Attachments <1.3.1 - Auth Bypass
CVSS 5.3
CVE-2025-49978 MEDIUM
eyecix JobSearch <2.9.0 - Auth Bypass
CVSS 4.3
CVE-2025-6329 MEDIUM
ScriptAndTools Real Estate Management System 1.0 - Auth Bypass
CVSS 5.4
CVE-2025-5195 MEDIUM
Gitlab < 17.10.7 - IDOR
CVSS 4.3
CVE-2025-40661 HIGH
ACC DM Corporative Cms < 2025.01 - IDOR
CVSS 7.5
CVE-2025-40660 HIGH
ACC DM Corporative Cms < 2025.01 - IDOR
CVSS 7.5
CVE-2025-40659 HIGH
ACC DM Corporative Cms < 2025.01 - IDOR
CVSS 7.5
CVE-2025-40658 HIGH
ACC DM Corporative Cms < 2025.01 - IDOR
CVSS 7.5
CVE-2025-4691 MEDIUM
Free Booking Plugin - Insecure Direct Object Reference
CVSS 5.3
CVE-2025-40650 HIGH
Clickedu - Info Disclosure
CVE-2025-5182 MEDIUM
Summerpearlgroup Vacation Rental Mana... - Improper Authorization
CVSS 4.3
CVE-2025-5181 LOW
Summerpearlgroup Vacation Rental Management Platform - Code Injection
CVSS 3.5
CVE-2025-20114 MEDIUM
Cisco Unified Intelligence Center - Privilege Escalation
CVSS 4.3
CVE-2025-24969 MEDIUM
iTop <3.2.1 - Info Disclosure
CVSS 5.0
CVE-2025-3769 MEDIUM
LatePoint - Calendar Booking Plugin - Info Disclosure
CVSS 5.3
CVE-2025-3605 CRITICAL
Frontend Login & Registration Blocks <1.0.7 - Privilege Escalation
CVSS 9.8
CVE-2025-3811 CRITICAL
Iqonic Wpbookit < 1.0.3 - IDOR
CVSS 9.8
CVE-2025-3810 CRITICAL
Iqonic Wpbookit < 1.0.3 - IDOR
CVSS 9.8
Details
Vulnerabilities 1,573
Exploit Likelihood High