CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,794 vulnerabilities with CWE-639
CVE-2025-12919 LOW
evershop < 2.0.1 - Authorization Bypass via Order UUID Manipulation
CVSS 3.7
CVE-2025-12918 LOW
yungifez Skuul School Management System <2.6.5 - Info Disclosure
CVSS 3.1
CVE-2025-12353 MEDIUM
WPFunnels <3.6.2 - Unauthorized Registration
CVSS 5.3
CVE-2025-11748 MEDIUM
Groups plugin for WordPress <3.7.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-64431 HIGH
Zitadel 4.0.0-rc.1-4.6.2 - Authenticated Insecure Direct Object Reference via V2Beta API
CVE-2025-12854 LOW
newbee-mall-plus <2.4.1 - Auth Bypass
CVSS 3.7
CVE-2025-58627 CRITICAL
Miraculous Core Plugin < 2.0.9 - Auth Bypass
CVSS 9.8
CVE-2025-63248 HIGH
DWSurvey 6.14.0 - Privilege Escalation
CVSS 7.5
CVE-2025-11690 HIGH
CFMOTO RIDE - Unauthorized Data Access via VehicleID Parameter
CVSS 8.5
CVE-2025-0987 CRITICAL
CB Project Ltd. Co. CVLand <20251103 - Auth Bypass
CVSS 9.9
CVE-2025-12623 LOW
fushengqian fuint <41e26be8a2c609413a0feaa69bdad33a71ae8032 - Auth ...
CVSS 3.1
CVE-2025-6574 HIGH
Service Finder Bookings <6.1 - Privilege Escalation
CVSS 8.8
CVE-2025-5949 HIGH
Service Finder Bookings <6.0 - Privilege Escalation
CVSS 8.8
CVE-2025-61876 MEDIUM
Inforcer Platform <2.0.153 - Info Disclosure
CVSS 5.0
CVE-2025-64283 MEDIUM
Rometheme RTMKit <1.6.7 - Auth Bypass
CVSS 6.5
CVE-2025-12351 MEDIUM
Honeywell S35 Series Cameras - Privilege Escalation
CVSS 6.8
CVE-2025-12288 MEDIUM
Bdtask Pharmacy Management System < 9.4 - Improper Authorization in User Profile Handler
CVSS 4.3
CVE-2025-12283 MEDIUM
code-projects Client Details System 1.0 - Improper Authorization
CVSS 4.3
CVE-2025-12270 MEDIUM
LearnHouse <98dfad76aad70711a8113f6c1fdabfccf10509ca - Info Disclosure
CVSS 4.3
CVE-2025-34293 HIGH
GN4 Publishing System <2.6 - Info Disclosure
CVE-2025-11957 HIGH
Devolutions Server < 2025.2.14.0 - Authenticated Authorization Bypass via Temporary Access Workflow
CVSS 8.4
CVE-2025-49952 MEDIUM
Houzez <= 4.2.5 - Authorization Bypass via User-Controlled Key
CVSS 6.5
CVE-2025-6833 MEDIUM
All in One Time Clock Lite - WordPress <2.0 - Insecure Direct Objec...
CVSS 4.3
CVE-2025-10570 MEDIUM
WooCommerce Flexible Refund Return Order <1.0.38 - Auth Bypass
CVSS 4.3
CVE-2025-60511 MEDIUM
Moodle OpenAI Chat Block plugin 3.0.1 - IDOR
CVSS 4.3
Details
Vulnerabilities 1,794
Exploit Likelihood High