CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,822 vulnerabilities with CWE-639
CVE-2023-48641
HIGH
Archer Platform 6.x <6.14 P1 HF2 - Privilege Escalation
CVSS 7.5
CVE-2023-6341
MEDIUM
Catalis CMS360 - Unauthenticated Sensitive Document Access via URL Parameter Manipulation
CVSS 5.3
CVE-2023-6226
MEDIUM
WP Shortcodes Plugin - Insecure Direct Object Reference
CVSS 4.3
CVE-2023-49298
HIGH
OpenZFS <2.1.14, <2.2.2 - Info Disclosure
CVSS 7.5
CVE-2023-33706
MEDIUM
SysAid < 23.2.15 - Unauthenticated Insecure Direct Object Reference via EmailHtmlSourceIframe.jsp or ShowMessage.jsp
CVSS 6.5
CVE-2023-47316
MEDIUM
Headwind MDM Web panel 5.22.1 - Incorrect Access Control
CVSS 5.4
CVE-2023-48304
MEDIUM
Nextcloud Server 22.0.0-22.2.10.15, 25.0.0-25.0.10 - Authorization Bypass via Birthday Calendar Toggle
CVSS 4.3
CVE-2023-6144
CRITICAL
Dev blog v1.0 - Unauthenticated Account Takeover via User Cookie
CVSS 9.1
CVE-2023-38884
HIGH
openSIS Classic 9.0 - Unauthenticated Insecure Direct Object Reference via Student Files Endpoint
CVSS 7.5
CVE-2023-43900
MEDIUM
EMSigner 2.8.7 - Authorization Bypass via DocumentID and EncryptedDocumentId Parameter Manipulation
CVSS 6.5
CVE-2023-46446
MEDIUM
asyncssh < 2.14.1 - Rogue Session Attack via Packet Injection
CVSS 6.8
CVE-2023-5544
MEDIUM
moodle 3.9.0-3.9.23 and <4.3.0-rc2 - Stored Cross-Site Scripting and Insecure Direct Object Reference in Wiki Comments
CVSS 6.5
CVE-2023-45380
HIGH
silbersaiten order_duplicator <= 1.1.7 - Unauthenticated Personal Information Disclosure
CVSS 8.8
CVE-2023-41356
MEDIUM
NCSIST ManageEngine MDM - Path Traversal
CVSS 6.5
CVE-2023-38965
CRITICAL
Lost and Found Information System 1.0 - Privilege Escalation
CVSS 9.8
CVE-2023-4836
MEDIUM
WordPress File Sharing Plugin <2.0.5 - Info Disclosure
CVSS 4.3
CVE-2023-46478
HIGH
minCal 1.0.0 - Code Execution via customer_data Parameter
CVSS 8.8
CVE-2023-3998
MEDIUM
wpDiscuz <= 7.6.3 - Unauthenticated Data Modification via userRate Function
CVSS 5.3
CVE-2023-3869
MEDIUM
wpDiscuz <= 7.6.3 - Unauthenticated Comment Rating Manipulation via voteOnComment Function
CVSS 5.3
CVE-2023-43668
CRITICAL
Apache InLong 1.4.0-1.8.0 - Authorization Bypass via Sensitive Parameter Check Bypass
CVSS 9.8
CVE-2023-45393
MEDIUM
GRANDING UTime Master v9.0.7-Build:Apr 4,2023 - Authenticated Information Disclosure via IDOR
CVSS 6.5
CVE-2023-45396
MEDIUM
Elenos ETG150 Firmware 3.12 - Authorization Bypass via Insecure Direct Object Reference
CVSS 6.5
CVE-2023-44981
CRITICAL
Apache ZooKeeper < 3.7.2 - Authorization Bypass via Missing SASL Instance Part
CVSS 9.1
CVE-2023-44249
MEDIUM
FortiAnalyzer and FortiManager < 7.2.3 - Authorization Bypass via Crafted HTTP Requests
CVSS 4.3
CVE-2023-42455
HIGH
Wazuh Dashboard 4.4.0-4.4.1 - Authorization Bypass via API Key Exposure
CVSS 8.8
Details
Vulnerabilities
1,822
Exploit Likelihood
High