CWE-639
2,515 CVEs • Abstraction: Base • Likelihood of Exploit: High
Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVEs (2,515)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Getnexx 4Nxal 100 Firmware Nxg 100b FirmwareNxg 200 Firmware+1 moreJun 17, 2026 Apr 4, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could retrieve device history, set device settings, and retrieve device informa...Show more |
1Getnexx 4Nxal 100 Firmware Nxg 100b FirmwareNxg 200 Firmware+1 moreJun 17, 2026 Apr 4, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The listed versions of Nexx Smart Home devices lack proper access control when executing actions. An attacker with a valid NexxHome deviceId could send API requests that the affected devices would execute. |
An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request. |
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within U...Show more |
WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this vulnerability to access files belonging to other users by modifying th...Show more |
Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack. |
3Debian DinoFedoraproject3Debian Linux DinoFedoraJun 17, 2026 Mar 24, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a g...Show more |
Authenticated users were able to enumerate other users' names via the learning plans page. |
Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Authentication Bypass, Authentication Abuse. This issue affects DigiKent: before 23.03.20. |
1Woocommerce Multiple Customer Addresses & Shipping Project 1Woocommerce Multiple Customer Addresses & Shipping Jun 17, 2026 Mar 20, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high pr...Show more |
Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. |
1Play With Docker 1Play With Docker Jun 17, 2026 Mar 16, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Play With Docker is a browser-based Docker playground. Versions 0.0.2 and prior are vulnerable to domain hijacking. Because CORS configuration was not correct, an attacker could use `play-with-docker.com` as an example a...Show more |
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. |
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored key uses username format characters. Any user who logged in within 24 hours. A token can be forged...Show more |
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16. |
Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the e...Show more |
1Biltema 2Baby Camera Firmware Ip Camera FirmwareJun 17, 2026 Feb 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information. |
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susceptible to type juggling in versions up to, and including, 1.2.5. This makes it possible for unauthe...Show more |
1Thingsforrestaurants 1Quick Restaurant Menu Jun 17, 2026 Jan 27, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the fact that during menu item deletion/modification, the plugin do...Show more |
1Instructure 1Canvas Learning Management Service Jun 17, 2026 Jan 26, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url). |