Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private
Authorization Bypass Through User-Controlled Key vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce P
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges vi
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not valid
A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is so
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGr
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_b
A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This impacts the function get_agent_executio
A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Affected is the function delete_agent/stop_s
A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the f
A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionali
A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the fil
A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseFo
A vulnerability was identified in AstrBotDevs AstrBot 4.24.2. This affects the function astr_main_agent of the file astr
A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_t
Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.
A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_
A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettl
A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is a
A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/das
A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknow
A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig
A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurv
A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView o
A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the fil
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown fu
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vuln
A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing o
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditi
Improper authorization vulnerability exists in RICOH Streamline NX 3.5.1 to 24R3. If a man-in-the-middle attack is condu
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy mat
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any a
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file owne
LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29,
LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel.
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
Cross-repository issue/comment attachment re-linking can expose private attachment content
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti
OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing byp
solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entr
A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started