CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,575 vulnerabilities with CWE-639
CVE-2023-2958
CRITICAL
Orjinyazilim Ats Pro < 20230714 - IDOR
CVSS 9.8
CVE-2023-3700
MEDIUM
Easyappointments < 1.5.0 - IDOR
CVSS 6.3
CVE-2023-2190
MEDIUM
GitLab CE/EE <15.11.10-16.0.6-16.1.1 - Info Disclosure
CVSS 6.5
CVE-2023-3105
HIGH
LearnDash LMS <4.6.0 - Info Disclosure
CVSS 8.8
CVE-2023-30960
MEDIUM
Foundry Job-Tracker <4.645.0 - Info Disclosure
CVSS 4.3
CVE-2023-30956
MEDIUM
Foundry Comments <2.267.0 - Info Disclosure
CVSS 5.3
CVE-2023-3219
MEDIUM
Eventon < 2.1.2 - IDOR
CVSS 5.3
CVE-2023-37242
CRITICAL
Huawei Emui - IDOR
CVSS 9.8
CVE-2023-3063
HIGH
SP Project & Document Manager <4.67 - Insecure Direct Object Reference
CVSS 8.8
CVE-2023-32352
MEDIUM
Apple Ipados < 16.5 - IDOR
CVSS 5.5
CVE-2023-23679
MEDIUM
Jshelpdesk < 2.7.7 - IDOR
CVSS 4.6
CVE-2023-26428
MEDIUM
Open-Xchange AppSuite Backend - Information Disclosure via Snippet ID
CVSS 6.5
CVE-2023-21131
HIGH
Google Android - IDOR
CVSS 7.8
CVE-2023-34000
HIGH
WooCommerce Stripe Payment Gateway <7.4.0 - Info Disclosure
CVSS 7.5
CVE-2023-3048
CRITICAL
TMT Lockcell <15 - Auth Bypass
CVSS 9.8
CVE-2023-1889
MEDIUM
Directorist <7.5.4 - Info Disclosure
CVSS 6.5
CVE-2023-0694
MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 6.5
CVE-2023-0693
MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 6.5
CVE-2023-0692
MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 4.3
CVE-2023-0691
MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 4.3
CVE-2023-0688
MEDIUM
Wpmet Metform Elementor Contact Form Builder - Information Disclosure
CVSS 6.5
CVE-2023-0985
HIGH
Mbconnectline Mbconnect24 < 2.13.3 - IDOR
CVSS 8.8
CVE-2023-33956
MEDIUM
Kanboard <1.2.30 - IDOR
CVSS 4.3
CVE-2023-3066
HIGH
Mobatime mobile app <1.3.20 - Auth Bypass
CVSS 8.1
CVE-2023-32310
HIGH
Dataease < 1.18.7 - IDOR
CVSS 8.1
Details
Vulnerabilities
1,575
Exploit Likelihood
High