CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,827 vulnerabilities with CWE-639
CVE-2022-4811
HIGH
usememos/memos <0.9.1 - Auth Bypass
CVSS 8.3
CVE-2022-4806
MEDIUM
GitHub usememos/memos <0.9.1 - Auth Bypass
CVSS 5.3
CVE-2022-4803
HIGH
usememos/memos <0.9.1 - Auth Bypass
CVSS 8.8
CVE-2022-4802
MEDIUM
GitHub usememos/memos <0.9.1 - Auth Bypass
CVSS 5.4
CVE-2022-4799
MEDIUM
memos < 0.9.1 - Authorization Bypass Through User-Controlled Key
CVSS 6.5
CVE-2022-4798
MEDIUM
memos < 0.9.1 - Authorization Bypass Through User-Controlled Key
CVSS 5.3
CVE-2022-46179
CRITICAL
LiuOS <= 0.1.0 - Authentication Bypass via GITHUB_ACTIONS Environment Variable
CVSS 9.2
CVE-2022-4686
CRITICAL
GitHub repository usememos/memos <0.9.0 - Auth Bypass
CVSS 9.8
CVE-2022-3805
HIGH
Jeg Elementor Kit <2.5.6 - Auth Bypass
CVSS 8.6
CVE-2022-3794
MEDIUM
Jeg Elementor Kit <2.5.6 - Auth Bypass
CVSS 5.4
CVE-2022-31683
MEDIUM
Concourse 6.0.0-6.7.8 and 7.0.0-7.8.2 - Authorization Bypass via Team Name Parameter
CVSS 5.4
CVE-2022-3876
MEDIUM
Click Studios Passwordstate - Auth Bypass
CVSS 4.3
CVE-2022-4505
HIGH
OpenEMR < 7.0.0.2 - Authorization Bypass Through User-Controlled Key
CVSS 8.8
CVE-2022-4097
MEDIUM
All-In-One Security (AIOS) <5.0.8 - Open Redirect
CVSS 5.3
CVE-2022-38765
MEDIUM
Canon Medical Informatics Vitrea Vision <7.7.76.1 - Privilege Escal...
CVSS 6.5
CVE-2022-2808
HIGH
Algan Software Prens <2.1.11 - ORM Injection
CVSS 8.8
CVE-2022-3995
MEDIUM
TeraWallet <= 1.4.3 - Authenticated Insecure Direct Object Reference via lock_unlock_terawallet AJAX Action
CVSS 4.3
CVE-2022-43326
HIGH
Telos Alliance Omnia MPX Node <1.4 - IDOR
CVSS 7.5
CVE-2022-24187
HIGH
Ourphoto App 1.4.1 - Info Disclosure
CVSS 7.5
CVE-2022-3589
HIGH
Miele AppWash - Authorization Bypass via API Endpoint
CVSS 8.1
CVE-2022-43492
MEDIUM
Comments - wpDiscuz 7.4.2 - Authenticated Insecure Direct Object Reference
CVSS 4.3
CVE-2022-44005
MEDIUM
BACKCLICK Professional 5.9.63 - Info Disclosure
CVSS 5.3
CVE-2022-42129
MEDIUM
Liferay Portal 7.3.2-7.4.3.4 & DXP 7.3-7.4 GA - IDOR via Dynamic Data Mapping Form Instance Record ID
CVSS 4.3
CVE-2022-3413
MEDIUM
GitLab 14.5-15.3.5 15.4-15.4.4 15.5-15.5.2 - Authorization Bypass in Audit Events Display
CVSS 4.3
CVE-2022-40206
MEDIUM
wpForo Forum <= 2.0.5 - Insecure Direct Object Reference in Post Privacy Setting
CVSS 6.3
Details
Vulnerabilities
1,827
Exploit Likelihood
High