CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,830 vulnerabilities with CWE-639
CVE-2019-19616
MEDIUM
Microsoft Dynamics NAV <2017 - IDOR
CVSS 4.3
CVE-2019-16546
MEDIUM
Jenkins Google Compute Engine Plugin <4.1.1 - Man-in-the-middle
CVSS 5.9
CVE-2019-15815
MEDIUM
ZyXEL P-1302-T10D <2.00(ABBX.3) - Privilege Escalation
CVSS 6.5
CVE-2019-17605
HIGH
eyecomms eyeCMS < 2019-10-15 - Authorization Bypass via Mass Assignment
CVSS 8.8
CVE-2019-17604
MEDIUM
eyecomms eyeCMS < 2019-10-15 - Insecure Direct Object Reference via Candidate ID Parameter
CVSS 4.3
CVE-2019-8235
MEDIUM
Magento 2.1.0-2.1.16, 2.2.0-2.2.7 - Authenticated Insecure Direct Object Reference
CVSS 6.5
CVE-2019-17574
CRITICAL
Popup Maker < 1.8.13 - Unauthenticated Authorization Bypass via do_action Function
CVSS 9.1
CVE-2019-17382
CRITICAL
Zabbix < 4.4 - Unauthenticated Authorization Bypass via Dashboard View Action
CVSS 9.1
CVE-2019-17050
HIGH
Voyager < 1.2.7 - Authenticated Arbitrary File Read and Delete via Compass
CVSS 7.2
CVE-2019-16723
MEDIUM
Cacti < 1.2.6 - Authenticated Authorization Bypass via local_graph_id Parameter
CVSS 4.3
CVE-2019-16403
HIGH
Webkul Bagisto <0.1.5 - Info Disclosure
CVSS 8.8
CVE-2019-15725
HIGH
GitLab 12.0-12.2.1 - Authorization Bypass via Epic Notes API
CVSS 7.5
CVE-2019-14725
MEDIUM
CentOS Web Panel <0.9.8.851 - Info Disclosure
CVSS 4.3
CVE-2019-14724
HIGH
CentOS Web Panel <0.9.8.851 - Info Disclosure
CVSS 7.5
CVE-2019-14721
MEDIUM
CentOS Web Panel 0.9.8.851 - Info Disclosure
CVSS 6.5
CVE-2019-14246
MEDIUM
CentOS Web Panel <0.9.8.851 - Info Disclosure
CVSS 6.5
CVE-2019-14245
MEDIUM
CentOS Web Panel <0.9.8.851 - Info Disclosure
CVSS 6.5
CVE-2019-14932
HIGH
Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 - Authorization Bypass via selApp Parameter
CVSS 7.5
CVE-2019-7950
HIGH
Magento <2.1.18-2.3.2 - Auth Bypass
CVSS 7.5
CVE-2019-7925
MEDIUM
Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Insecure Direct Object Reference
CVSS 4.9
CVE-2019-7890
HIGH
Magento <2.1.18-2.3.2 - Info Disclosure
CVSS 7.3
CVE-2019-7872
MEDIUM
Magento 2.1-2.1.17, 2.2-2.2.8, 2.3-2.3.1 - Authenticated Insecure Direct Object Reference
CVSS 6.5
CVE-2019-7864
MEDIUM
Magento 2.1.0-2.1.17, 2.2.0-2.2.8, 2.3.0-2.3.1 - Insecure Direct Object Reference in RSS Feeds
CVSS 5.3
CVE-2019-7854
HIGH
Magento <2.1.18-2.3.2 - Info Disclosure
CVSS 7.5
CVE-2019-13605
HIGH
CentOS Web Panel 0.9.8.838-0.9.8.846 - Auth Bypass
CVSS 8.8
Details
Vulnerabilities
1,830
Exploit Likelihood
High