CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,576 vulnerabilities with CWE-639
CVE-2022-0691 CRITICAL
NPM url-parse <1.5.9 - Auth Bypass
CVSS 9.8
CVE-2022-0686 CRITICAL
NPM url-parse <1.5.8 - Auth Bypass
CVSS 9.1
CVE-2022-24979 MEDIUM
Mittwald Varnishcache < 2.0.1 - IDOR
CVSS 5.3
CVE-2022-25336 MEDIUM
Ibexa EZ Platform Kernel < 1.3.12 - IDOR
CVSS 5.3
CVE-2022-0639 MEDIUM
NPM url-parse <1.5.7 - Auth Bypass
CVSS 5.3
CVE-2022-0613 MEDIUM
NPM urijs <1.19.8 - Auth Bypass
CVSS 6.5
CVE-2022-0512 MEDIUM
NPM url-parse <1.5.6 - Auth Bypass
CVSS 5.3
CVE-2022-21713 MEDIUM
Grafana < 7.5.15 - Incorrect Authorization
CVSS 4.3
CVE-2022-22832 CRITICAL
Servisnet Tessa - IDOR
CVSS 9.8
CVE-2022-22828 HIGH
Synametrics Synaman < 5.0 - IDOR
CVSS 7.5
CVE-2022-23856 MEDIUM
Saviynt EIC <5.5 SP2.x - Info Disclosure
CVSS 5.3
CVE-2022-0266 MEDIUM
Packagist remdex/livehelperchat <3.92v - Auth Bypass
CVSS 6.6
CVE-2021-47721 HIGH
Orangescrum - IDOR
CVSS 8.8
CVE-2021-3991 MEDIUM
Dolibarr Erp/crm < 20.0.2 - Improper Authorization
CVSS 4.3
CVE-2021-27700 HIGH
SOCIFI Socifi Guest - Privilege Escalation
CVSS 7.6
CVE-2021-37577 MEDIUM
Bluetooth Core Specifications 2.1-5.3 - Info Disclosure
CVSS 6.8
CVE-2021-33223 HIGH
SeedDMS 6.0.15 - Privilege Escalation
CVSS 8.8
CVE-2021-36400 MEDIUM
Moodle - Privilege Escalation
CVSS 5.3
CVE-2021-36539 MEDIUM
Instructure Canvas LMS - Info Disclosure
CVSS 6.5
CVE-2021-36906 LOW
Expresstech Quiz And Survey Master < 7.3.6 - IDOR
CVSS 2.7
CVE-2021-36865 LOW
Quizandsurveymaster Quiz And Survey Master < 7.3.4 - IDOR
CVSS 3.8
CVE-2021-4142 MEDIUM
Candlepin < 3.1.28-2 - Authentication Bypass
CVSS 5.5
CVE-2021-24655 HIGH
Wpusermanager WP User Manager < 2.6.3 - IDOR
CVSS 7.5
CVE-2021-24800 MEDIUM
DW Question & Answer Pro <1.3.4 - Info Disclosure
CVSS 4.3
CVE-2021-46416 HIGH
SUNNY TRIPOWER 5.0 - Info Disclosure
CVSS 8.1
Details
Vulnerabilities 1,576
Exploit Likelihood High