Vulnerabilities (CVE)

Filtered by CWE-639
Total 543 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47316 1 H-mdm 1 Headwind Mdm 2024-02-05 N/A 5.4 MEDIUM
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control. The Web panel allows users to gain access to potentially sensitive API calls such as listing users and their data, file management API calls and audit-related API calls.
CVE-2022-43450 1 Xwp 1 Stream 2024-02-05 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through 3.9.2.
CVE-2023-48783 1 Fortinet 1 Fortiportal 2024-02-05 N/A 5.4 MEDIUM
An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and below may allow a remote authenticated user with at least read-only permissions to access to other organization endpoints via crafted GET requests.
CVE-2023-32799 1 Woocommerce 1 Shipping Multiple Addresses 2024-02-05 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addresses: from n/a through 3.8.3.
CVE-2023-48641 1 Archerirm 1 Archer 2024-02-05 N/A 8.8 HIGH
Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation could potentially exploit this vulnerability by manipulating application resource references in user requests to bypass authorization checks, in order to gain execute access to AWF application resources.
CVE-2023-41796 1 Sunshinephotocart 1 Sunshine Photo Cart 2024-02-05 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in WP Sunshine Sunshine Photo Cart: Free Client Galleries for Photographers.This issue affects Sunshine Photo Cart: Free Client Galleries for Photographers: from n/a before 3.0.0.
CVE-2023-49812 1 Wppa 1 Wp Photo Album Plus 2024-02-05 N/A 7.5 HIGH
Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
CVE-2023-6341 1 Catalisgov 1 Cms360 2024-02-05 N/A 5.3 MEDIUM
Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation.
CVE-2023-51503 1 Automattic 1 Woopayments 2024-02-05 N/A 7.5 HIGH
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 6.9.2.
CVE-2023-32747 1 Automattic 1 Woocommerce Bookings 2024-02-05 N/A 7.5 HIGH
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.
CVE-2023-51502 2024-02-05 N/A 9.8 CRITICAL
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1.
CVE-2023-35916 1 Automattic 1 Woopayments 2024-02-05 N/A 7.5 HIGH
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from n/a through 5.9.0.
CVE-2023-46311 1 Gvectors 1 Wpdiscuz 2024-02-05 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3.
CVE-2023-38884 1 Os4ed 1 Opensis 2024-02-05 N/A 7.5 HIGH
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filename>'
CVE-2023-47191 1 Kainelabs 1 Youzify 2024-02-05 N/A 6.5 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2.
CVE-2023-38513 1 Meowapps 1 Photo Engine 2024-02-05 N/A 5.4 MEDIUM
Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engine (Media Organizer & Lightroom): from n/a through 6.2.5.
CVE-2023-36520 1 Zackgrossbart 1 Editorial Calendar 2024-02-05 N/A 8.1 HIGH
Authorization Bypass Through User-Controlled Key vulnerability in MarketingFire Editorial Calendar.This issue affects Editorial Calendar: from n/a through 3.7.12.
CVE-2023-7031 1 Avaya 1 Aura Experience Portal 2024-02-05 N/A 4.3 MEDIUM
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. Affected versions include 8.0.x and 8.1.x, prior to 8.1.2 patch 0402. Versions prior to 8.0 are end of manufacturer support.
CVE-2023-6223 1 Thimpress 1 Learnpress 2024-02-05 N/A 4.3 MEDIUM
The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.7 via the /wp-json/lp/v1/profile/course-tab REST API due to missing validation on the 'userID' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve the details of another user's course progress.
CVE-2023-3700 1 Easyappointments 1 Easyappointments 2024-02-05 N/A 4.3 MEDIUM
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.