Weaknesses of type CWE-639

1,590 results
CVE-2026-21447HIGHBagisto has IDOR in Customer Order Reorder FunctionalityEPSS 0.3%CVE-2026-46441HIGHFlowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource ReassignmentEPSS 0.3%CVE-2026-33356HIGHMeari MQTT broker missing per-device subscribe ACLEPSS 0.3%CVE-2026-32697MEDIUMSuiteCRM: RecordHandler::getRecord() missing ACLAccess('view') check allows any authenticated user to read any record (IDOR)EPSS 0.3%CVE-2024-55186MEDIUMAn IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messageEPSS 0.3%CVE-2026-25745MEDIUMOpenEMR's Message Update Ignores Patient idEPSS 0.3%CVE-2026-30886MEDIUMNew API: IDOR in VideoProxy allows cross-user video content access via missing ownership checkEPSS 0.3%CVE-2026-29069MEDIUMCraft has an unauthenticated activation email trigger with potential user enumerationEPSS 0.3%CVE-2026-42725MEDIUMWordPress Checkout Files Upload for WooCommerce plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2024-12099MEDIUMDollie Hub – Build Your Own WordPress Cloud Platform <= 6.2.0 - Authenticated (Contributor+) Post DisclosureEPSS 0.3%CVE-2025-62242MEDIUMInsecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 20EPSS 0.3%CVE-2026-48599HIGHAuthorization bypass via path binding override in elixir-grpc/grpc HTTP transcodingEPSS 0.3%CVE-2025-69202MEDIUMaxios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary HeaderEPSS 0.3%CVE-2026-55197HIGHHermes WebUI < 0.51.443 - Broken Access Control in /api/session EndpointEPSS 0.3%CVE-2026-55198HIGHHermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export EndpointEPSS 0.3%CVE-2026-22383HIGHWordPress PawFriends - Pet Shop and Veterinary WordPress theme theme <= 1.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-39968HIGHTypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview EndpointEPSS 0.3%CVE-2026-25120MEDIUMGogs Allows Cross-Repository Comment Deletion via DeleteCommentEPSS 0.3%CVE-2026-11987MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' ParameterEPSS 0.3%CVE-2024-31898MEDIUMIBM InfoSphere Information Server data modificationEPSS 0.3%