/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to aut
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-se
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2
An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u
Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessi
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repos
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a
An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor
Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The I
WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the Customiz
A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API cal
Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using anoth
Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypa
Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PU
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code e
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijackin
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. Us
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege esc
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authe
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v
Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows P
D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints.
Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0
Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Trackin
The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_ap
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in
PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticat
A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability
The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible M
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_ap
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypas
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow`
Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Di
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object R
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate u
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allo
The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 t
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignme
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 1,243 CVE records associated with CWE-639 in our database. Of these, 79 are critical severity, 338 are high severity, and 618 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started