CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,811 vulnerabilities with CWE-639
CVE-2024-43239
MEDIUM
Masteriyo - LMS <1.11.4 - Auth Bypass
CVSS 4.3
CVE-2024-42464
MEDIUM
upKeeper Manager <5.1.9 - Auth Bypass
CVSS 6.5
CVE-2024-42463
MEDIUM
upKeeper Manager <5.1.9 - Auth Bypass
CVSS 6.5
CVE-2024-27730
CRITICAL
Friendica 2023.12 - Authorization Bypass and Remote Code Execution via Calendar Event cid Parameter
CVSS 9.8
CVE-2024-6534
MEDIUM
Directus v10.13.0 - Privilege Escalation
CVSS 4.3
CVE-2024-21981
MEDIUM
AMD Secure Processor - Info Disclosure
CVSS 5.7
CVE-2024-39642
MEDIUM
ThimPress LearnPress <4.2.6.8.2 - Auth Bypass
CVSS 6.5
CVE-2024-7658
MEDIUM
projectsend <r1605 - Info Disclosure
CVSS 5.3
CVE-2024-3035
MEDIUM
GitLab 8.12-17.0.5, 17.1-17.1.3, 17.2-17.2.1 - Authorization Bypass via LFS Token
CVSS 6.8
CVE-2024-6357
MEDIUM
OpenText ArcSight Intelligence - Info Disclosure
CVSS 6.3
CVE-2024-7438
MEDIUM
SimpleMachines SMF 2.1.4 - Improper Control of Resource Identifiers
CVSS 4.3
CVE-2024-7437
MEDIUM
SimpleMachines SMF 2.1.4 - Improper Control of Resource Identifiers
CVSS 5.4
CVE-2024-41254
MEDIUM
litestream < 0.3.13 - Man-in-the-Middle Attack via Insecure SSH Host Key Verification
CVSS 5.3
CVE-2024-38701
MEDIUM
Academy LMS < 2.0.4 - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2024-34457
MEDIUM
Apache StreamPark < 2.1.4 - Authorization Bypass via User Token
CVSS 6.5
CVE-2024-5977
MEDIUM
GiveWP <= 3.13.0 - Authenticated IDOR via 'handleRequest'
CVSS 5.4
CVE-2024-5619
CRITICAL
PruvaSoft Informatics Apinizer Mgmt Console <2024.05.1 - Auth Bypass
CVSS 9.6
CVE-2024-38447
HIGH
NATO NCI ANET 3.4.1 - Info Disclosure
CVSS 8.1
CVE-2024-38446
MEDIUM
NATO NCI ANET 3.4.1 - Privilege Escalation
CVSS 6.5
CVE-2024-6410
MEDIUM
ProfileGrid <= 5.8.9 - Authenticated IDOR via pm_upload_image
CVSS 4.3
CVE-2024-39901
MEDIUM
OpenSearch Observability < 2.14 - Authorization Bypass via Private Tenant Resource Access
CVSS 4.2
CVE-2024-39900
MEDIUM
OpenSearch Observability < 2.14 - Authorization Bypass via Private Tenant Resource Access
CVSS 5.4
CVE-2024-39897
MEDIUM
Zot <2.1.0 - Unauthorized Blob Read via Dedupe Cache
CVSS 4.3
CVE-2024-21759
MEDIUM
FortiPortal 7.0.0-7.0.6 and 7.2.0 - Authorization Bypass via HTTP/HTTPS Requests
CVSS 4.3
CVE-2024-4341
MEDIUM
Extreme XDS < 3928 - Authorization Bypass via User-Controlled Key
CVSS 6.5
Details
Vulnerabilities
1,811
Exploit Likelihood
High