CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,574 vulnerabilities with CWE-639
CVE-2024-53406
HIGH
Espressif Esp-idf - IDOR
CVSS 8.8
CVE-2024-13887
MEDIUM
WordPress - Insecure Direct Object Reference
CVSS 5.3
CVE-2024-12114
MEDIUM
Fooplugins Foogallery < 2.4.30 - IDOR
CVSS 4.3
CVE-2024-11216
HIGH
PozitifIK Pik Online <3.1.5 - Privilege Escalation
CVSS 7.6
CVE-2024-8261
HIGH
Proliz Software OBS <24.0927 - Auth Bypass
CVSS 7.5
CVE-2024-10925
MEDIUM
Gitlab < 17.7.6 - IDOR
CVSS 5.3
CVE-2024-13832
MEDIUM
Uncodethemes Ultra Addons Lite For Elementor < 1.1.8 - IDOR
CVSS 4.3
CVE-2024-50693
CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-50689
CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-50687
CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-50686
CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-50685
CRITICAL
Sungrowpower Isolarcloud < 2024-10-31 - IDOR
CVSS 9.1
CVE-2024-13873
MEDIUM
Wpjobportal WP Job Portal < 2.2.9 - IDOR
CVSS 4.3
CVE-2024-13855
MEDIUM
Nilambar Prime Addons For Elementor < 2.0.1 - Improper Access Control
CVSS 4.3
CVE-2024-13854
MEDIUM
Nicheaddons Education Addon < 1.3.1 - Improper Access Control
CVSS 4.3
CVE-2024-13719
MEDIUM
Peprodev Ultimate Invoice < 2.0.8 - Missing Authorization
CVSS 5.3
CVE-2024-13740
MEDIUM
Metagauss Profilegrid < 5.9.4.3 - IDOR
CVSS 4.3
CVE-2024-13692
MEDIUM
Wpswings Return Refund And Exchange F... - Improper Authorization
CVSS 5.4
CVE-2024-34520
HIGH
Mavenir SCE Application Provisioning Portal - Authorization Bypass
CVSS 8.8
CVE-2024-13601
MEDIUM
Majesticsupport Majestic Support < 1.0.6 - IDOR
CVSS 4.3
CVE-2024-13841
MEDIUM
Builder Shortcode Extras - Info Disclosure
CVSS 4.3
CVE-2024-39033
HIGH
Newgensoft OmniDocs <11.0_SP1_03_006 - Info Disclosure
CVSS 7.5
CVE-2024-9097
LOW
Zohocorp Manageengine Endpoint Central < 11.3.2428.26 - IDOR
CVSS 3.5
CVE-2024-12046
MEDIUM
Medical Addon for Elementor <1.6.2 - Info Disclosure
CVSS 4.3
CVE-2024-13607
MEDIUM
JS Help Desk & Support Plugin <2.8.8 - Insecure Direct Object Refer...
CVSS 4.3
Details
Vulnerabilities
1,574
Exploit Likelihood
High