CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,796 vulnerabilities with CWE-639
CVE-2025-27561
MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Room Rename
CVSS 5.3
CVE-2025-26857
MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Device Rename
CVSS 5.3
CVE-2025-25276
MEDIUM
Growatt Cloud Portal <= 3.6.0 - Device Hijacking
CVSS 5.3
CVE-2025-24850
MEDIUM
Growatt Cloud Portal <= 3.6.0 - Information Disclosure
CVSS 5.3
CVE-2025-24315
MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Device Addition
CVSS 5.3
CVE-2025-31949
MEDIUM
Growatt Cloud Portal < 3.6.0 - Authenticated Authorization Bypass via Plant ID
CVSS 5.3
CVE-2025-31941
MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Username Enumeration
CVSS 5.3
CVE-2025-31933
MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Username Enumeration via API Query
CVSS 5.3
CVE-2025-31357
MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Username
CVSS 5.3
CVE-2025-30514
MEDIUM
Smart Device Collections - Info Disclosure
CVSS 5.3
CVE-2025-30254
MEDIUM
Growatt Cloud Portal <= 3.6.0 - Information Disclosure
CVSS 5.3
CVE-2025-27939
HIGH
Growatt Cloud Portal < 3.6.0 - Unauthenticated Account Takeover via Email Change
CVSS 7.5
CVE-2025-27938
MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Information Disclosure via User-Controlled Key
CVSS 5.3
CVE-2025-27568
MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Email Disclosure via Password Reset Request
CVSS 5.3
CVE-2025-24487
MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Username Enumeration via API Query
CVSS 5.3
CVE-2025-3575
HIGH
Deporsite >= 05.29.0907 < 05.29.0907 - Insecure Direct Object Reference via idUsuario Parameter
CVE-2025-3574
HIGH
Deporsite >=v05.29.0907 <v05.29.0907 - Insecure Direct Object Reference via idUsuario Parameter
CVE-2025-3537
MEDIUM
Tutorials-Website Employee Management System 1.0 - Improper Authorization via ID Parameter in /admin/update-user.php
CVSS 5.3
CVE-2025-3536
MEDIUM
Tutorials-Website Employee Management System 1.0 - Improper Authorization in Delete User Function
CVSS 6.5
CVE-2025-3292
MEDIUM
WordPress <4.1.3 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-3282
MEDIUM
User Registration & Membership - Insecure Direct Object Reference
CVSS 5.3
CVE-2025-32373
MEDIUM
Dnnsoftware Dotnetnuke < 9.13.8 - IDOR
CVSS 6.5
CVE-2025-2526
HIGH
Streamit theme <4.0.2 - Privilege Escalation
CVSS 8.8
CVE-2025-22931
HIGH
OS4ED openSIS 7.0-9.1 - Unauthenticated Insecure Direct Object Reference in Staff Files Component
CVSS 7.5
CVE-2025-31867
MEDIUM
JoomSky JS Job Manager <2.0.2 - Auth Bypass
CVSS 5.4
Details
Vulnerabilities
1,796
Exploit Likelihood
High