CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,574 vulnerabilities with CWE-639
CVE-2024-9262 MEDIUM
User Meta - User Profile Builder <3.1 - Insecure Direct Object Refe...
CVSS 6.5
CVE-2024-10779 MEDIUM
Codeless Cowidgets Elementor Addons < 1.2.0 - IDOR
CVSS 5.3
CVE-2024-52313 MEDIUM
data.all - Info Disclosure
CVSS 4.3
CVE-2024-43438 HIGH
Moodle < 4.1.12 - IDOR
CVSS 7.5
CVE-2024-51559 MEDIUM
Wave 2.0 - Privilege Escalation
CVSS 6.5
CVE-2024-48217 HIGH
SiSMART v7.4.0 - Privilege Escalation
CVSS 8.8
CVE-2024-37277 HIGH
Strangerstudios Paid Memberships Pro < 3.0.5 - IDOR
CVSS 7.5
CVE-2024-10654 MEDIUM
Totolink Lr350 Firmware - Improper Authorization
CVSS 5.3
CVE-2024-51066 HIGH
Phpgurukul Beauty Parlour Management System - IDOR
CVSS 7.5
CVE-2024-9700 MEDIUM
Wpmudev Forminator Forms < 1.36.1 - IDOR
CVSS 5.3
CVE-2024-10452 LOW
Grafana - IDOR
CVSS 2.2
CVE-2024-7474 HIGH
Lunary < 1.3.4 - IDOR
CVSS 8.1
CVE-2024-7473 MEDIUM
Lunary - IDOR
CVSS 6.5
CVE-2024-50483 CRITICAL
Tareqhasan Meetup < 0.1 - IDOR
CVSS 9.8
CVE-2024-10439 MEDIUM
Sun.net Ehrd Ctms < 10.8 - IDOR
CVSS 5.3
CVE-2024-9637 HIGH
Igexsolutions Wpschoolpress < 2.2.11 - IDOR
CVSS 8.8
CVE-2024-10121 HIGH
wfh45678 Radar <1.0.8 - Auth Bypass
CVSS 7.3
CVE-2024-9263 CRITICAL
WP Timetics <1.0.25 - Privilege Escalation
CVSS 9.8
CVE-2024-9862 CRITICAL
Miniorange Otp Verification With Firebase < 3.6.1 - IDOR
CVSS 9.8
CVE-2024-9215 HIGH
WordPress PublishPress Authors <4.7.1 - Privilege Escalation
CVSS 8.8
CVE-2024-8040 HIGH
3DSwym <Release 3DEXPERIENCE R2024x - Auth Bypass
CVSS 7.7
CVE-2024-49388 CRITICAL
Acronis Cyber Protect <38690 - Info Disclosure
CVSS 9.1
CVE-2024-9687 HIGH
Dueclic WP 2fa With Telegram < 3.1 - IDOR
CVSS 8.8
CVE-2024-46528 MEDIUM
Kubesphere < 4.1.3 - IDOR
CVSS 4.3
CVE-2024-47495 MEDIUM
Juniper Networks Junos OS Evolved - Auth Bypass
CVSS 6.7
Details
Vulnerabilities 1,574
Exploit Likelihood High