CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,574 vulnerabilities with CWE-639
CVE-2024-8601 MEDIUM
TechExcel Back Office Software <1.0.0 - Info Disclosure
CVSS 6.5
CVE-2024-8428 HIGH
ForumWP - Privilege Escalation
CVSS 8.8
CVE-2024-1744 HIGH
Accordors Accord Ors < 7.3.2.1 - Missing Authorization
CVSS 7.5
CVE-2024-8292 CRITICAL
Plechevandrey Wp-recall < 16.26.9 - IDOR
CVSS 9.8
CVE-2024-8123 MEDIUM
WP Extended <3.0.8 - Insecure Direct Object Reference
CVSS 5.4
CVE-2024-45232 MEDIUM
powermail <12.3.5 - IDOR
CVSS 5.3
CVE-2024-40395 MEDIUM
PTC ThingWorx <9.5.0 - Info Disclosure
CVSS 6.5
CVE-2024-43916 MEDIUM
Dylanjkotze Zephyr Project Manager < 3.3.103 - IDOR
CVSS 4.3
CVE-2024-8158 MEDIUM
lib9p - Privilege Escalation
CVSS 6.5
CVE-2024-7848 MEDIUM
Mediajedi User Private Files < 2.1.1 - IDOR
CVSS 4.3
CVE-2024-43350 MEDIUM
Propovoice CRM <1.7.6.4 - Auth Bypass
CVSS 5.3
CVE-2024-43322 MEDIUM
Dylan James Zephyr Project Manager <3.3.100 - Auth Bypass
CVSS 5.4
CVE-2024-43315 HIGH
Stripe Payments For WooCommerce <1.9.1 - Auth Bypass
CVSS 7.5
CVE-2024-43288 MEDIUM
wpForo Forum <2.3.4 - Auth Bypass
CVSS 4.3
CVE-2024-43266 MEDIUM
WP Job Portal <2.1.6 - Auth Bypass
CVSS 5.4
CVE-2024-43239 MEDIUM
Masteriyo - LMS <1.11.4 - Auth Bypass
CVSS 4.3
CVE-2024-42464 MEDIUM
upKeeper Manager <5.1.9 - Auth Bypass
CVSS 6.5
CVE-2024-42463 MEDIUM
upKeeper Manager <5.1.9 - Auth Bypass
CVSS 6.5
CVE-2024-27730 CRITICAL
Friendica <2023.12 - RCE
CVSS 9.8
CVE-2024-6534 MEDIUM
Directus v10.13.0 - Privilege Escalation
CVSS 4.3
CVE-2024-21981 MEDIUM
AMD Secure Processor - Info Disclosure
CVSS 5.7
CVE-2024-39642 MEDIUM
ThimPress LearnPress <4.2.6.8.2 - Auth Bypass
CVSS 6.5
CVE-2024-7658 MEDIUM
projectsend <r1605 - Info Disclosure
CVSS 5.3
CVE-2024-3035 MEDIUM
Gitlab < 17.0.6 - IDOR
CVSS 6.8
CVE-2024-6357 MEDIUM
OpenText ArcSight Intelligence - Info Disclosure
CVSS 6.3
Details
Vulnerabilities 1,574
Exploit Likelihood High