CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,574 vulnerabilities with CWE-639
CVE-2024-53406 HIGH
Espressif Esp-idf - IDOR
CVSS 8.8
CVE-2024-13887 MEDIUM
WordPress - Insecure Direct Object Reference
CVSS 5.3
CVE-2024-12114 MEDIUM
Fooplugins Foogallery < 2.4.30 - IDOR
CVSS 4.3
CVE-2024-11216 HIGH
PozitifIK Pik Online <3.1.5 - Privilege Escalation
CVSS 7.6
CVE-2024-8261 HIGH
Proliz Software OBS <24.0927 - Auth Bypass
CVSS 7.5
CVE-2024-10925 MEDIUM
Gitlab < 17.7.6 - IDOR
CVSS 5.3
CVE-2024-13832 MEDIUM
Uncodethemes Ultra Addons Lite For Elementor < 1.1.8 - IDOR
CVSS 4.3
CVE-2024-50693 CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-50689 CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-50687 CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-50686 CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-50685 CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-13873 MEDIUM
Wpjobportal WP Job Portal < 2.2.9 - IDOR
CVSS 4.3
CVE-2024-13855 MEDIUM
Nilambar Prime Addons For Elementor < 2.0.1 - Improper Access Control
CVSS 4.3
CVE-2024-13854 MEDIUM
Nicheaddons Education Addon < 1.3.1 - Improper Access Control
CVSS 4.3
CVE-2024-13719 MEDIUM
Peprodev Ultimate Invoice < 2.0.8 - Missing Authorization
CVSS 5.3
CVE-2024-13740 MEDIUM
Metagauss Profilegrid < 5.9.4.3 - IDOR
CVSS 4.3
CVE-2024-13692 MEDIUM
Wpswings Return Refund And Exchange F... - Improper Authorization
CVSS 5.4
CVE-2024-34520 HIGH
Mavenir SCE Application Provisioning Portal - Authorization Bypass
CVSS 8.8
CVE-2024-13601 MEDIUM
Majesticsupport Majestic Support < 1.0.6 - IDOR
CVSS 4.3
CVE-2024-13841 MEDIUM
Builder Shortcode Extras - Info Disclosure
CVSS 4.3
CVE-2024-39033 HIGH
Newgensoft OmniDocs <11.0_SP1_03_006 - Info Disclosure
CVSS 7.5
CVE-2024-9097 LOW
Zohocorp Manageengine Endpoint Central < 11.3.2428.26 - IDOR
CVSS 3.5
CVE-2024-12046 MEDIUM
Medical Addon for Elementor <1.6.2 - Info Disclosure
CVSS 4.3
CVE-2024-13607 MEDIUM
JS Help Desk & Support Plugin <2.8.8 - Insecure Direct Object Refer...
CVSS 4.3
Details
Vulnerabilities 1,574
Exploit Likelihood High