CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,794 vulnerabilities with CWE-639
CVE-2025-52670
MEDIUM
Revive Adserver < 5.5.2 - Authorization Bypass via Banner Deletion
CVSS 6.5
CVE-2025-65034
HIGH
rallly < 4.5.4 - Authenticated Authorization Bypass via PollId Parameter
CVSS 8.1
CVE-2025-65033
HIGH
rallly < 4.5.4 - Authenticated Authorization Bypass in Poll Management
CVSS 8.1
CVE-2025-65032
MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via ParticipantId Parameter
CVSS 6.5
CVE-2025-65031
MEDIUM
rallly < 4.5.4 - Authenticated User Impersonation via Comment AuthorName Field
CVSS 6.5
CVE-2025-65030
HIGH
rallly < 4.5.4 - Authenticated Authorization Bypass via Comment Deletion API
CVSS 7.1
CVE-2025-65029
HIGH
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference in Participant Deletion Endpoint
CVSS 8.1
CVE-2025-65028
MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via ParticipantId Parameter
CVSS 6.5
CVE-2025-65021
CRITICAL
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Finalization
CVSS 9.1
CVE-2025-65020
MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Duplication Endpoint
CVSS 6.5
CVE-2025-12766
MEDIUM
BlackBerry AtHoc OnPrem <7.21 - Info Disclosure
CVSS 5.0
CVE-2025-12427
MEDIUM
YITH WooCommerce Wishlist <4.10.0 - Info Disclosure
CVSS 5.3
CVE-2025-63513
MEDIUM
kishan0725 Hospital Management System v4 - Info Disclosure
CVSS 6.5
CVE-2025-12524
MEDIUM
Post Type Switcher <4.0.0 - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-63291
MEDIUM
Alteryx Server 2022.1.1.42654-2024.1 - Info Disclosure
CVSS 5.4
CVE-2025-8855
HIGH
Optimus Software Brokerage Automation <1.1.71 - Auth Bypass
CVSS 8.1
CVE-2025-64706
MEDIUM
typebot 3.9.0-3.12.9 - Authenticated Insecure Direct Object Reference in API Token Management
CVSS 5.0
CVE-2025-41069
MEDIUM
T-Innova DeporSite DSuite 2025 >=v02.14.1115 <v02.14.1115 - Authorization Bypass via idUsuario Parameter
CVE-2025-12366
MEDIUM
Pagelayer <2.0.5 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-64523
HIGH
filebrowser < 2.45.1 - Authenticated Insecure Direct Object Reference in Share Deletion
CVSS 8.8
CVE-2025-12903
HIGH
Braintree For WooCommerce <3.2.78 - Auth Bypass
CVSS 7.5
CVE-2025-12833
MEDIUM
GeoDirectory - WP Business Directory Plugin <2.8.139 - Insecure Dir...
CVSS 4.3
CVE-2025-12087
MEDIUM
Woocommerce plugin <1.1.22 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-12126
MEDIUM
The Total Book Project plugin - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-11532
MEDIUM
Wisly plugin - Insecure Direct Object Reference
CVSS 5.3
Details
Vulnerabilities
1,794
Exploit Likelihood
High