CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,575 vulnerabilities with CWE-639
CVE-2023-6504
MEDIUM
User Profile Builder <3.10.7 - Info Disclosure
CVSS 4.3
CVE-2023-6506
MEDIUM
WP 2FA - Insecure Direct Object Reference
CVSS 4.3
CVE-2023-6223
MEDIUM
LearnPress <4.2.5.7 - Info Disclosure
CVSS 4.3
CVE-2023-6630
MEDIUM
Contact Form 7 - Insecure Direct Object Reference
CVSS 4.3
CVE-2023-48783
MEDIUM
PortiPortal <7.2.1-<6.0.14-<5.3.8 - Auth Bypass
CVSS 5.4
CVE-2023-49251
HIGH
SIMATIC CN 4100 < V2.7 - Privilege Escalation
CVSS 8.8
CVE-2023-51502
HIGH
WooCommerce Stripe Payment Gateway <7.6.1 - Auth Bypass
CVSS 7.5
CVE-2023-50342
HIGH
Hcltech Dryice Myxalytics - IDOR
CVSS 7.1
CVE-2023-45893
HIGH
Floorsight Customer Portal Q3 2023 - Info Disclosure
CVSS 7.5
CVE-2023-45892
HIGH
Floorsight Insights Q3 2023 - Info Disclosure
CVSS 7.5
CVE-2023-51503
MEDIUM
WooPayments <6.9.2 - Auth Bypass
CVSS 5.9
CVE-2023-50267
MEDIUM
Metersphere < 2.10.10 - Improper Privilege Management
CVSS 4.3
CVE-2023-46646
MEDIUM
GitHub Enterprise Server <3.17.19-3.11.0 - Info Disclosure
CVSS 5.3
CVE-2023-49765
MEDIUM
Blazzdev Rate MY Post < 3.4.2 - IDOR
CVSS 4.3
CVE-2023-47191
MEDIUM
Kainelabs Youzify < 1.2.3 - IDOR
CVSS 6.5
CVE-2023-32799
MEDIUM
Woocommerce Shipping Multiple Addresses < 3.8.3 - IDOR
CVSS 6.5
CVE-2023-32747
MEDIUM
Automattic Woocommerce Bookings < 1.15.78 - IDOR
CVSS 5.4
CVE-2023-35916
HIGH
WooPayments <5.9.0 - Auth Bypass
CVSS 7.5
CVE-2023-35914
HIGH
WooCommerce Woo Subscriptions <5.1.2 - Auth Bypass
CVSS 7.5
CVE-2023-36520
MEDIUM
MarketingFire Editorial Calendar <3.7.12 - Auth Bypass
CVSS 5.4
CVE-2023-35876
HIGH
Automattic Woocommerce Square < 3.8.2 - IDOR
CVSS 8.1
CVE-2023-46311
LOW
wpDiscuz <7.6.3 - Auth Bypass
CVSS 2.7
CVE-2023-41796
MEDIUM
Sunshinephotocart Sunshine Photo Cart < 3.0 - IDOR
CVSS 5.3
CVE-2023-38513
MEDIUM
Jordy Meow Photo Engine <6.2.5 - Auth Bypass
CVSS 5.4
CVE-2023-37871
HIGH
Automattic Woocommerce Gocardless < 2.5.7 - IDOR
CVSS 8.2
Details
Vulnerabilities
1,575
Exploit Likelihood
High