CVE Database

9+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS

9 results for "CWE-639"

CVE-2026-7573
5.0 MEDIUM

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete …

May 6, 2026
CVE-2025-46387
8.8 HIGH

CWE-639 Authorization Bypass Through User-Controlled Key

Aug 6, 2025
CVE-2025-46386
8.8 HIGH

CWE-639 Authorization Bypass Through User-Controlled Key

Aug 6, 2025
CVE-2024-10497
8.8 HIGH

CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of …

Jan 17, 2025
CVE-2023-47543
5.4 MEDIUM

An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other …

Nov 12, 2024
CVE-2023-44254
5.0 MEDIUM

An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a …

Sep 10, 2024
CVE-2023-40720
7.1 HIGH

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP …

May 14, 2024
CVE-2024-23112
8.0 HIGH

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy …

Mar 12, 2024
CVE-2023-48783
5.4 MEDIUM

An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, version 6.0.14 and below, version 5.3.8 and …

Jan 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.