CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,575 vulnerabilities with CWE-639
CVE-2023-38048 CRITICAL
Easyappointments < 1.5.0 - IDOR
CVSS 9.9
CVE-2023-38047 HIGH
Easyappointments < 1.5.0 - IDOR
CVSS 8.5
CVE-2023-3285 HIGH
BOLA - Privilege Escalation
CVSS 7.7
CVE-2023-49112 MEDIUM
Kiuwan - Info Disclosure
CVSS 6.5
CVE-2023-40720 HIGH
FortiVoiceEnterprise <7.0.1, <=6.4.8 - Auth Bypass
CVSS 7.1
CVE-2023-6897 MEDIUM
Wpfactory Ean For Woocommerce < 4.9.3 - IDOR
CVSS 4.3
CVE-2023-45808 MEDIUM
Combodo Itop < 2.7.10 - IDOR
CVSS 4.1
CVE-2023-51141 MEDIUM
ZKTeko BioTime <8.5.4 - Info Disclosure
CVSS 6.5
CVE-2023-6317 HIGH
secondscreen.gateway <7 - Privilege Escalation
CVSS 7.2
CVE-2023-6523 HIGH
ExtremePacs Extreme XDS <3914 - Auth Bypass
CVSS 8.8
CVE-2023-36483 MEDIUM
MASmobile Classic <1.16.18-1.7.24 - Auth Bypass
CVSS 6.5
CVE-2023-36238 MEDIUM
Bagisto <1.5.1 - Info Disclosure
CVSS 6.5
CVE-2023-6969 MEDIUM
Kylebjohnson User Shortcodes Plus < 2.0.2 - IDOR
CVSS 4.3
CVE-2023-7198 MEDIUM
Jeroensormani WP Dashboard Notes < 1.0.11 - IDOR
CVSS 4.3
CVE-2023-49339 MEDIUM
Ellucian Banner 9.17 - Info Disclosure
CVSS 6.5
CVE-2023-6724 HIGH
Simgesel Hearing Tracking System < 1.0 - IDOR
CVSS 8.8
CVE-2023-6515 HIGH
MIA-MED <1.0.7 - Auth Bypass
CVSS 8.8
CVE-2023-47022 MEDIUM
NCR Terminal Handler <1.5.1 - Info Disclosure
CVSS 6.5
CVE-2023-6983 MEDIUM
Josevega Display Custom Fields IN The... - IDOR
CVSS 4.3
CVE-2023-7199 MEDIUM
Relevanssi < 2.25.0 - IDOR
CVSS 5.3
CVE-2023-6384 MEDIUM
WP User Profile Avatar <1.0.1 - Auth Bypass
CVSS 4.3
CVE-2023-7031 MEDIUM
Avaya Aura Experience Portal < 8.1.2.0.0402 - Information Disclosure
CVSS 5.7
CVE-2023-36235 MEDIUM
Webkul QloApps <1.6.0 - Info Disclosure
CVSS 6.5
CVE-2023-6824 MEDIUM
Marvinlabs WP Customer Area < 8.2.1 - IDOR
CVSS 6.5
CVE-2023-6875 CRITICAL
Wordpress POST SMTP Account Takeover
CVSS 9.8
Details
Vulnerabilities 1,575
Exploit Likelihood High