Weaknesses of type CWE-639
1,591 resultsCVE-2026-3307MEDIUMAuthorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewersEPSS 0.3%CVE-2025-67919MEDIUMWordPress Woffice Core plugin <= 5.4.30 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-5142MEDIUMForeman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypassEPSS 0.3%CVE-2026-6571MEDIUMkodcloud KodExplorer systemRole.class.php roleGroupAction authorizationEPSS 0.3%CVE-2026-45671HIGHOpen WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletionEPSS 0.3%CVE-2026-46390MEDIUMHAX CMS has Unauthenticated Git Access via User-Controlled KeyEPSS 0.3%CVE-2026-6586MEDIUMTransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorizationEPSS 0.3%CVE-2025-39434MEDIUMWordPress Avatar plugin <= 0.1.4 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-1947HIGHNEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_idEPSS 0.3%CVE-2024-45329LOWA authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 EPSS 0.3%CVE-2026-32694MEDIUMInsecure Direct Object Reference attack via predictable secret ID in JujuEPSS 0.3%CVE-2026-1541MEDIUMAvada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object ReferenceEPSS 0.3%CVE-2026-40907MEDIUMWWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth TokensEPSS 0.3%CVE-2026-8786MEDIUMTencent WeKnora Config API Endpoint initialization.go getKnowledgeBaseForInitialization authorizationEPSS 0.3%CVE-2025-43827MEDIUMInsecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported verEPSS 0.3%CVE-2026-3124HIGHDownload Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id'EPSS 0.3%CVE-2025-9836MEDIUMmacrozheng mall paySuccess authorizationEPSS 0.3%CVE-2026-42863HIGHFlowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow ReassignmentEPSS 0.3%CVE-2025-68975MEDIUMWordPress Eagle Booking plugin <= 1.3.4.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-35045HIGHTandoor Recipes Affected by Private Recipe Exposure and Unauthorized ModificationEPSS 0.3%