Vulnerabilities > Authorization Bypass Through User-Controlled Key

DATE CVE VULNERABILITY TITLE RISK
2023-09-06 CVE-2020-10130 Authorization Bypass Through User-Controlled Key vulnerability in Searchblox
SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system.
network
low complexity
searchblox CWE-639
8.8
2023-09-04 CVE-2023-4587 Authorization Bypass Through User-Controlled Key vulnerability in Zkteco Zem800 Firmware 6.60
An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60.
local
low complexity
zkteco CWE-639
5.5
2023-08-24 CVE-2023-32078 Authorization Bypass Through User-Controlled Key vulnerability in Gravitl Netmaker
Netmaker makes networks with WireGuard.
network
low complexity
gravitl CWE-639
7.5
2023-08-14 CVE-2023-28481 Authorization Bypass Through User-Controlled Key vulnerability in Tigergraph 3.7.0
An issue was discovered in Tigergraph Enterprise 3.7.0.
network
low complexity
tigergraph CWE-639
8.8
2023-08-10 CVE-2023-37543 Authorization Bypass Through User-Controlled Key vulnerability in Cacti
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php.
network
low complexity
cacti CWE-639
7.5
2023-07-17 CVE-2023-2958 Authorization Bypass Through User-Controlled Key vulnerability in Orjinyazilim ATS PRO
Authorization Bypass Through User-Controlled Key vulnerability in Origin Software ATS Pro allows Authentication Abuse, Authentication Bypass.This issue affects ATS Pro: before 20230714.
network
low complexity
orjinyazilim CWE-639
critical
9.8
2023-07-17 CVE-2023-3700 Authorization Bypass Through User-Controlled Key vulnerability in Easyappointments
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
network
low complexity
easyappointments CWE-639
4.3
2023-07-13 CVE-2023-2190 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.10 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1.
network
low complexity
gitlab CWE-639
6.5
2023-07-10 CVE-2023-3219 Authorization Bypass Through User-Controlled Key vulnerability in Myeventon Eventon
The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.
network
low complexity
myeventon CWE-639
5.3
2023-07-06 CVE-2023-37242 Authorization Bypass Through User-Controlled Key vulnerability in Huawei Emui and Harmonyos
Vulnerability of commands from the modem being intercepted in the atcmdserver module.
network
low complexity
huawei CWE-639
critical
9.8