CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,796 vulnerabilities with CWE-639
CVE-2024-13694
HIGH
WooCommerce Wishlist < 1.8.7 - Unauthenticated Insecure Direct Object Reference via download_pdf_file()
CVSS 7.5
CVE-2024-13457
MEDIUM
WordPress - Insecure Direct Object Reference
CVSS 5.3
CVE-2024-10497
HIGH
PowerLogic HDPM6000 v0.62.7 - Authenticated Privilege Escalation via Modified HTTPS Requests
CVSS 8.8
CVE-2024-11146
MEDIUM
TrueFiling <3.1.112.19 - Info Disclosure
CVSS 6.3
CVE-2024-10775
MEDIUM
Piotnet Addons For Elementor <2.4.32 - Info Disclosure
CVSS 4.3
CVE-2024-12116
MEDIUM
Unlimited Theme Addon For Elementor & WooCommerce <1.2.1 - Info Dis...
CVSS 4.3
CVE-2024-11915
MEDIUM
RRAddons for Elementor < 1.1.0 - Authenticated Information Exposure via Popup Block
CVSS 4.3
CVE-2024-42169
HIGH
HCL MyXalytics - Authorization Bypass via Insecure Direct Object Reference
CVSS 7.1
CVE-2024-12472
MEDIUM
Post Duplicator < 2.36 - Authenticated Information Exposure via mtphr_duplicate_post()
CVSS 4.3
CVE-2024-10215
CRITICAL
WPBookit <1.6.4 - Privilege Escalation
CVSS 9.8
CVE-2024-44450
MEDIUM
AIMS eCrew - Authorization Bypass Through User-Controlled Key
CVSS 5.4
CVE-2024-12131
MEDIUM
WP Job Portal < 2.2.5 - Authenticated Insecure Direct Object Reference via User-Controlled Key
CVSS 4.3
CVE-2024-12132
MEDIUM
WP Job Portal < 2.2.4 - Authenticated Insecure Direct Object Reference via User-Controlled Key
CVSS 4.3
CVE-2024-13040
HIGH
QOCA aim - Authorization Bypass via User ID Parameter
CVSS 8.8
CVE-2024-52294
MEDIUM
Khoj < 1.29.10 - Authenticated Insecure Direct Object Reference in Subscription Endpoint
CVSS 4.3
CVE-2024-12335
MEDIUM
Avada (Fusion) Builder <= 3.11.12 - Authenticated Information Exposure via handle_clone_post Function
CVSS 4.3
CVE-2024-12103
MEDIUM
Content No Cache: prevent specific content from being cached <0.1.2...
CVSS 5.3
CVE-2024-10797
MEDIUM
Full Screen Menu for Elementor <= 1.0.7 - Authenticated Information Exposure via Elementor Widget
CVSS 4.3
CVE-2024-55471
MEDIUM
Oqtane.Framework - Insecure Direct Object Reference in UserController via ID Parameter
CVSS 6.5
CVE-2024-55186
MEDIUM
Oqtane.Framework 6.0.0 - Authenticated Insecure Direct Object Reference via Notification ID Manipulation
CVSS 4.3
CVE-2024-55506
HIGH
CodeAstro Complaint Management System v1.0 - Authorization Bypass via delete.php id Parameter
CVSS 8.8
CVE-2024-55231
MEDIUM
PHPGurukul Online Notes Sharing Management System 1.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2024-4464
HIGH
Synology Media Server <2.2.0-3325 - Auth Bypass
CVSS 7.5
CVE-2024-12061
MEDIUM
Events Addon for Elementor <= 2.2.3 - Authenticated Information Exposure via naevents_elementor_template Shortcode
CVSS 4.3
CVE-2024-9819
MEDIUM
NextGeography NG Analyser <2.2.711 - Auth Bypass
CVSS 6.5
Details
Vulnerabilities
1,796
Exploit Likelihood
High