Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2023-02-03 CVE-2022-34138 Authorization Bypass Through User-Controlled Key vulnerability in Biltema Baby Camera Firmware and IP Camera Firmware
Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information.
network
low complexity
biltema CWE-639
7.5
2023-01-26 CVE-2021-36539 Authorization Bypass Through User-Controlled Key vulnerability in Instructure Canvas Learning Management Service 20200729
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).
network
low complexity
instructure CWE-639
6.5
2023-01-18 CVE-2022-45927 Authorization Bypass Through User-Controlled Key vulnerability in Opentext Extended ECM
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).
network
low complexity
opentext CWE-639
8.8
2023-01-17 CVE-2022-40319 Authorization Bypass Through User-Controlled Key vulnerability in Lsoft Listserv 17.0
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL.
network
low complexity
lsoft CWE-639
7.5
2023-01-14 CVE-2023-22471 Authorization Bypass Through User-Controlled Key vulnerability in Nextcloud Deck
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud.
network
low complexity
nextcloud CWE-639
4.3
2022-12-28 CVE-2022-4798 Authorization Bypass Through User-Controlled Key vulnerability in Usememos Memos
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
network
low complexity
usememos CWE-639
5.3
2022-12-28 CVE-2022-4799 Authorization Bypass Through User-Controlled Key vulnerability in Usememos Memos
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
network
low complexity
usememos CWE-639
6.5
2022-12-28 CVE-2022-4802 Authorization Bypass Through User-Controlled Key vulnerability in Usememos Memos
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
network
low complexity
usememos CWE-639
5.4
2022-12-28 CVE-2022-4803 Authorization Bypass Through User-Controlled Key vulnerability in Usememos Memos
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
network
low complexity
usememos CWE-639
8.8
2022-12-28 CVE-2022-4806 Authorization Bypass Through User-Controlled Key vulnerability in Usememos Memos
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
network
low complexity
usememos CWE-639
5.3