CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,811 vulnerabilities with CWE-639
CVE-2024-4843
MEDIUM
Trellix ePolicy Orchestrator - Privilege Escalation via Insecure Direct Object Reference
CVSS 4.3
CVE-2024-4279
MEDIUM
Tutor LMS - Insecure Direct Object Reference
CVSS 6.5
CVE-2024-4819
MEDIUM
Campcodes Online Laundry Management System 1.0 - Improper Authorization in admin_class.php
CVSS 4.3
CVE-2024-4817
MEDIUM
Campcodes Online Laundry Management System 1.0 - Info Disclosure
CVSS 6.3
CVE-2024-33818
HIGH
Globitel KSA SpeechLog v8.1 - Info Disclosure
CVSS 7.5
CVE-2024-1693
MEDIUM
SP Project & Document Manager - Info Disclosure
CVSS 4.3
CVE-2024-4538
HIGH
Janto Ticketing Software <4.3r10 - Info Disclosure
CVSS 7.5
CVE-2024-4537
HIGH
Janto Ticketing Software <4.3r10 - Info Disclosure
CVSS 7.5
CVE-2024-34383
MEDIUM
SEOPress < 7.7.1 - Authorization Bypass Through User-Controlled Key
CVSS 5.3
CVE-2024-2346
MEDIUM
FileBird WordPress Plugin <= 5.6.3 - Authenticated IDOR via Folder Deletion
CVSS 5.4
CVE-2024-24312
HIGH
Vaales Technologies V_QRS <2024-01-17 - Info Disclosure
CVSS 7.5
CVE-2024-33383
HIGH
novel-plus < 4.3.0 - Arbitrary File Read via filePath Parameter
CVSS 7.5
CVE-2024-28320
HIGH
Hospital Management System 1.0 - Authorization Bypass via Patient Edit User Endpoint
CVSS 7.6
CVE-2024-33542
MEDIUM
Crelly Slider <= 1.4.5 - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2024-4294
MEDIUM
PHPGurukul Doctor Appointment Management System 1.0 - Improper Cont...
CVSS 6.3
CVE-2024-33668
CRITICAL
Zammad < 6.3.0 - Authorization Bypass via Upload Cache FormID Brute Force
CVSS 9.1
CVE-2024-32823
MEDIUM
FeedbackWP Rate my Post - WP Rating System <= 3.4.4 - Insecure Direct Object Reference
CVSS 5.3
CVE-2024-32808
MEDIUM
ProfileGrid < 5.7.9 - Authorization Bypass Through User-Controlled Key
CVSS 5.4
CVE-2024-32772
MEDIUM
ProfileGrid < 5.7.9 - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2024-32166
HIGH
Webid v1.2.1 - Horizontal Privilege Escalation
CVSS 8.8
CVE-2024-32683
MEDIUM
Wpmet Wp Ultimate Review <= 2.2.5 - Authorization Bypass Through User-Controlled Key
CVSS 5.3
CVE-2024-32604
MEDIUM
Plechev Andrey WP-Recall <16.26.5 - Auth Bypass
CVSS 4.3
CVE-2024-1626
HIGH
lunary < 1.0.0 - Authenticated Insecure Direct Object Reference in Project Update Endpoint
CVSS 8.1
CVE-2024-22439
MEDIUM
HPE FlexFabric/FlexNetwork - Privilege Escalation
CVSS 6.9
CVE-2024-1625
MEDIUM
Lunary 0.3.0 - Insecure Direct Object Reference in Project Deletion
CVSS 6.5
Details
Vulnerabilities
1,811
Exploit Likelihood
High