CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,574 vulnerabilities with CWE-639
CVE-2024-10670 MEDIUM
Nicheaddons Primary Addon For Elementor < 1.6.3 - IDOR
CVSS 4.3
CVE-2024-10868 MEDIUM
Themelooks Enter Addons < 2.1.9 - IDOR
CVSS 4.3
CVE-2024-50395 HIGH
Qnap Media Streaming Add-on < 500.1.1.6 - IDOR
CVSS 8.8
CVE-2024-10666 MEDIUM
WP plugin - Info Disclosure
CVSS 4.3
CVE-2024-10796 MEDIUM
If-So Dynamic Content Personalization <1.9.2.1 - Info Disclosure
CVSS 4.3
CVE-2024-10782 MEDIUM
Theme Builder For Elementor <1.2.2 - Info Disclosure
CVSS 4.3
CVE-2024-10696 MEDIUM
Codeastrology Ultraaddons < 1.1.8 - IDOR
CVSS 4.3
CVE-2024-10671 MEDIUM
Bplugins Button Block < 1.1.5 - IDOR
CVSS 4.3
CVE-2024-48899 MEDIUM
Moodle < 4.4.4 - Improper Access Control
CVSS 4.3
CVE-2024-10855 HIGH
Sirv < 7.3.1 - IDOR
CVSS 8.1
CVE-2024-11318 HIGH
AbsysNet <2.3.1 - Info Disclosure
CVSS 7.5
CVE-2024-10795 MEDIUM
Popularis Extra <1.2.7 - Info Disclosure
CVSS 4.3
CVE-2024-52511 MEDIUM
Nextcloud Tables < 0.8.0 - IDOR
CVSS 6.3
CVE-2024-52507 LOW
Nextcloud Tables < 0.8.1 - IDOR
CVSS 3.5
CVE-2024-50651 MEDIUM
Geeeeeeeek Java Shop - IDOR
CVSS 6.5
CVE-2024-10794 MEDIUM
Boostify Header Footer Builder - Info Disclosure
CVSS 4.3
CVE-2024-10174 HIGH
WP Project Manager <2.6.13 - Insecure Direct Object Reference
CVSS 7.3
CVE-2024-10778 MEDIUM
Staxwp Buddybuilder < 1.8.0 - IDOR
CVSS 4.3
CVE-2024-10695 MEDIUM
Futuriowp Futurio Extra < 2.0.14 - IDOR
CVSS 4.3
CVE-2024-11073 MEDIUM
Mayurik Hospital Management System - Improper Authorization
CVSS 4.3
CVE-2024-10688 MEDIUM
Attesa Extra <1.4.2 - Info Disclosure
CVSS 4.3
CVE-2024-10770 MEDIUM
Envothemes Envo Extra < 1.9.4 - IDOR
CVSS 4.3
CVE-2024-10669 MEDIUM
WordPress Countdown Timer <1.2.4 - Info Disclosure
CVSS 4.3
CVE-2024-10667 MEDIUM
WordPress Content Slider Block <3.1.5 - Info Disclosure
CVSS 4.3
CVE-2024-10693 MEDIUM
Sktthemes Skt Addons For Elementor < 3.4 - IDOR
CVSS 4.3
Details
Vulnerabilities 1,574
Exploit Likelihood High