CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,830 vulnerabilities with CWE-639
CVE-2021-21324
MEDIUM
GLPI < 9.5.4 - Authenticated Insecure Direct Object Reference via Knowbase Search Form
CVSS 6.8
CVE-2021-21255
MEDIUM
GLPI 9.5.3 - Missing Authorization via Entity Switch IDOR
CVSS 5.8
CVE-2021-21022
MEDIUM
Magento < 2.3.6 - Insecure Direct Object Reference in Product Module
CVSS 5.3
CVE-2021-26024
MEDIUM
Nagios XI Favorites < 1.0.2 - Insecure Direct Object Reference
CVSS 5.3
CVE-2021-21013
HIGH
Magento <2.4.1-2.3.6 - Info Disclosure
CVSS 8.1
CVE-2021-21012
MEDIUM
Magento <2.4.1-2.3.6 - Info Disclosure
CVSS 5.3
CVE-2020-37094
CRITICAL
EspoCRM 5.8.5 - Authentication Bypass via Authorization Header Manipulation
CVSS 9.8
CVE-2020-37008
HIGH
EasyPMS 1.0.0 - Unauthenticated Authorization Bypass via SQL Query Manipulation
CVSS 7.5
CVE-2020-36923
CRITICAL
Sony BRAVIA Digital Signage <1.7.8 - Path Traversal
CVSS 9.8
CVE-2020-36895
HIGH
EIBIZ i-Media Server Digital Signage 3.8.0 - Info Disclosure
CVSS 7.5
CVE-2020-10130
HIGH
SearchBlox < 9.1 - Unauthenticated Business Logic Bypass for Super Admin Creation
CVSS 8.8
CVE-2020-6641
MEDIUM
FortiPresence < 20.1 - Authorization Bypass via Portal Manager or Portal Users Parameters
CVSS 4.3
CVE-2020-26679
MEDIUM
vFairs 3.3 - Unauthenticated Profile Modification and Arbitrary File Upload via User ID
CVSS 4.3
CVE-2020-36126
HIGH
PAXSTORE < 7.0.8_20200511171508 - Authenticated Privilege Escalation via Marketplace Endpoint Access Control Bypass
CVSS 8.1
CVE-2020-23722
HIGH
FUEL CMS <1.4.7 - Privilege Escalation
CVSS 8.8
CVE-2020-8297
MEDIUM
Nextcloud Deck <1.0.2 - Info Disclosure
CVSS 4.3
CVE-2020-13462
MEDIUM
Tufin SecureChange <R20-2 GA - IDOR
CVSS 5.7
CVE-2020-16194
MEDIUM
Opart Devis < 4.0.2 - Unauthenticated Insecure Direct Object Reference via Delivery and Invoice Address Fields
CVSS 5.3
CVE-2020-36231
MEDIUM
Atlassian Jira < 8.5.10 and 8.6.0-8.13.2 - Unauthenticated Board Metadata Exposure via IDOR
CVSS 4.3
CVE-2020-23449
HIGH
newbee-mall - Unauthenticated Authorization Bypass via NewBeeMallIndexConfigServiceImpl
CVSS 7.5
CVE-2020-29446
MEDIUM
Atlassian Fisheye & Crucible <4.8.5 - Info Disclosure
CVSS 5.3
CVE-2020-4918
MEDIUM
IBM Cloud Pak System 2.3.0.0-2.3.3.2 - Sensitive Information Disclosure via Insecure Direct Object Reference
CVSS 4.4
CVE-2020-35849
HIGH
MantisBT < 2.24.4 - Unauthenticated Information Disclosure via bugnote_id Parameter
CVSS 7.5
CVE-2020-29156
MEDIUM
WooCommerce < 4.7.0 - Unauthenticated Arbitrary Order Status Disclosure via order_id Parameter
CVSS 5.3
CVE-2020-26178
MEDIUM
tangro Business Workflow < 1.18.1 - Unauthenticated Attachment Download via Known Attachment ID
CVSS 5.3
Details
Vulnerabilities
1,830
Exploit Likelihood
High