CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,800 vulnerabilities with CWE-639
CVE-2024-10779
MEDIUM
Cowidgets - Elementor Addons <= 1.2.0 - Authenticated Information Exposure via ce_template Shortcode
CVSS 5.3
CVE-2024-52313
MEDIUM
data.all 1.0.0-2.6.0 - Authenticated Authorization Bypass via getDataset Query
CVSS 4.3
CVE-2024-43438
HIGH
Moodle 4.1.0-4.1.11 - Authorization Bypass in Feedback Bulk Messaging
CVSS 7.5
CVE-2024-51559
MEDIUM
63moons Wave 2.0 < 1.1.7 - Authenticated Authorization Bypass via API Parameter Manipulation
CVSS 6.5
CVE-2024-48217
HIGH
SiSMART v7.4.0 - Privilege Escalation
CVSS 8.8
CVE-2024-37277
HIGH
Paid Memberships Pro <= 3.0.4 - Authorization Bypass via User-Controlled Key
CVSS 7.5
CVE-2024-10654
MEDIUM
TOTOLINK LR350 <= 9.3.5u.6369 - Authorization Bypass via authCode Parameter
CVSS 5.3
CVE-2024-51066
HIGH
Phpgurukul Beauty Parlour Management System 1.1 - Unauthorized Data Access via IDOR in appointment-detail.php
CVSS 7.5
CVE-2024-9700
MEDIUM
Forminator Forms < 1.36.1 - Unauthenticated Insecure Direct Object Reference via Quiz Entry ID
CVSS 5.3
CVE-2024-10452
LOW
Grafana Organization Invites - Cross-Organization Deletion
CVSS 2.2
CVE-2024-7474
HIGH
lunary < 1.3.4 - Unauthenticated Insecure Direct Object Reference via ID Parameter
CVSS 8.1
CVE-2024-7473
MEDIUM
Lunary Evaluations - Insecure Direct Object Reference Prompt Update
CVSS 6.5
CVE-2024-50483
CRITICAL
Tareq Hasan Meetup <= 0.1 - Privilege Escalation via Authorization Bypass
CVSS 9.8
CVE-2024-10439
MEDIUM
sun.net ehrd_ctms < 10.8 - Unauthenticated Insecure Direct Object Reference
CVSS 5.3
CVE-2024-9637
HIGH
WPSchoolPress <= 2.2.10 - Authenticated Privilege Escalation via Email Update
CVSS 8.8
CVE-2024-10121
HIGH
wfh45678 Radar <1.0.8 - Auth Bypass
CVSS 7.3
CVE-2024-9263
CRITICAL
WP Timetics <1.0.25 - Privilege Escalation
CVSS 9.8
CVE-2024-9862
CRITICAL
Miniorange OTP Verification with Firebase <= 3.6.0 - Unauthenticated Arbitrary User Password Change
CVSS 9.8
CVE-2024-9215
HIGH
WordPress PublishPress Authors <4.7.1 - Privilege Escalation
CVSS 8.8
CVE-2024-8040
HIGH
3DSwym <Release 3DEXPERIENCE R2024x - Auth Bypass
CVSS 7.7
CVE-2024-49388
CRITICAL
Acronis Cyber Protect <38690 - Info Disclosure
CVSS 9.1
CVE-2024-9687
HIGH
WP 2FA with Telegram <= 3.0 - Authenticated Authentication Bypass via Insufficient Key Validation
CVSS 8.8
CVE-2024-46528
MEDIUM
KubeSphere 3.x-3.4.1, 3.x-3.5.0, 4.x<4.1.3 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2024-47495
MEDIUM
Juniper Networks Junos OS Evolved - Auth Bypass
CVSS 6.7
CVE-2024-7041
MEDIUM
open-webui v0.3.8 - Authorization Bypass via Memories Update API Endpoint
CVSS 6.5
Details
Vulnerabilities
1,800
Exploit Likelihood
High