CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,800 vulnerabilities with CWE-639
CVE-2024-8428
HIGH
ForumWP <= 2.0.2 - Authenticated Privilege Escalation via IDOR
CVSS 8.8
CVE-2024-1744
HIGH
Accord ORS < 7.3.2.1 - Authorization Bypass and Sensitive Data Exposure
CVSS 7.5
CVE-2024-8292
CRITICAL
WP-Recall < 16.26.9 - Unauthenticated Privilege Escalation via Order Creation
CVSS 9.8
CVE-2024-8123
MEDIUM
WP Extended <3.0.8 - Insecure Direct Object Reference
CVSS 5.4
CVE-2024-45232
MEDIUM
in2code powermail <7.5.0 and 11.0.0-12.3.5 - Unauthenticated Insecure Direct Object Reference via Mail Parameter
CVSS 5.3
CVE-2024-40395
MEDIUM
PTC ThingWorx <9.5.0 - Info Disclosure
CVSS 6.5
CVE-2024-43916
MEDIUM
Zephyr Project Manager <= 3.3.102 - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2024-8158
MEDIUM
9front lib9p < 2024-08-24 - Authorization Bypass via Tauth/Tattach Uname Mismatch
CVSS 6.5
CVE-2024-7848
MEDIUM
Mediajedi User Private Files < 2.1.1 - IDOR
CVSS 4.3
CVE-2024-43350
MEDIUM
Propovoice CRM <1.7.6.4 - Auth Bypass
CVSS 5.3
CVE-2024-43322
MEDIUM
Dylan James Zephyr Project Manager <3.3.100 - Auth Bypass
CVSS 5.4
CVE-2024-43315
HIGH
Stripe Payments For WooCommerce <1.9.1 - Auth Bypass
CVSS 7.5
CVE-2024-43288
MEDIUM
wpForo Forum < 2.3.4 - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2024-43266
MEDIUM
WP Job Portal <= 2.1.8 - Insecure Direct Object Reference
CVSS 5.4
CVE-2024-43239
MEDIUM
Masteriyo - LMS <1.11.4 - Auth Bypass
CVSS 4.3
CVE-2024-42464
MEDIUM
upKeeper Manager <5.1.9 - Auth Bypass
CVSS 6.5
CVE-2024-42463
MEDIUM
upKeeper Manager <5.1.9 - Auth Bypass
CVSS 6.5
CVE-2024-27730
CRITICAL
Friendica 2023.12 - Authorization Bypass and Remote Code Execution via Calendar Event cid Parameter
CVSS 9.8
CVE-2024-6534
MEDIUM
Directus v10.13.0 - Privilege Escalation
CVSS 4.3
CVE-2024-21981
MEDIUM
AMD Secure Processor - Info Disclosure
CVSS 5.7
CVE-2024-39642
MEDIUM
ThimPress LearnPress <4.2.6.8.2 - Auth Bypass
CVSS 6.5
CVE-2024-7658
MEDIUM
projectsend <r1605 - Info Disclosure
CVSS 5.3
CVE-2024-3035
MEDIUM
GitLab 8.12-17.0.5, 17.1-17.1.3, 17.2-17.2.1 - Authorization Bypass via LFS Token
CVSS 6.8
CVE-2024-6357
MEDIUM
OpenText ArcSight Intelligence - Info Disclosure
CVSS 6.3
CVE-2024-7438
MEDIUM
SimpleMachines SMF 2.1.4 - Improper Control of Resource Identifiers
CVSS 4.3
Details
Vulnerabilities
1,800
Exploit Likelihood
High