Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-639

MITRE ↗

CWE-639

174
CRITICAL
645
HIGH
1,343
MEDIUM
96
LOW
2,420 CVEs · Page 22/49
3.7
CVE-2026-14213

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated em

3.5
CVE-2025-14594

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and

3.5
CVE-2026-45159

Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16

3.3
CVE-2026-52839

Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appoi

3.1
CVE-2026-27838

wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calli

3.1
CVE-2026-2366

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated u

3.1
CVE-2026-4549

A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPor

3.1
CVE-2026-29071

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.

3.1
CVE-2026-4958

A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.s

3.1
CVE-2026-39967

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter r

3.1
CVE-2026-47715

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier

3.1
CVE-2026-47716

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes acces

3.1
CVE-2026-59215

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread pa

3.1
CVE-2026-52841

Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/co

3.1
CVE-2026-15058

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an aut

3.1
CVE-2026-63241

An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course compl

2.7
CVE-2026-25120

Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that

2.7
CVE-2026-32638

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `get

2.7
CVE-2026-39510

Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-ti

2.7
CVE-2026-6570

A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file

2.7
CVE-2026-3307

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin acc

2.7
CVE-2026-12102

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre

2.7
CVE-2026-61971

Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-pictu

2.7
CVE-2026-12906

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a r

2.7
CVE-2026-14195

The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning p

2.7
CVE-2026-15231

The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to acc

2.7
CVE-2026-16070

The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before upd

2.7
CVE-2026-16746

The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in

2.7
CVE-2026-16957

The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed

2.7
CVE-2026-58445

Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

2.7
CVE-2026-14825

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check before sa

2.7
CVE-2026-14826

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not perform a per-object ownership check on the RE

2.7
CVE-2026-19085

The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplic

2.7
CVE-2026-14187

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, al

2.7
CVE-2026-79615

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question ba

2.7
CVE-2026-81200

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order informa

2.6
CVE-2026-9248

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce

2.6
CVE-2026-45155

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 an

2.2
CVE-2026-14823

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of it

2.0
CVE-2026-47713

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti

CVE-2025-4596

Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging t

CVE-2026-1201

An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior

CVE-2026-1664

Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function with

0.0
CVE-2026-30825

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke e

CVE-2026-3020

Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user

CVE-2026-1496

Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that

CVE-2026-3321

A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIME

CVE-2026-5199

A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a vict

CVE-2026-40308

My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJA

CVE-2026-40480

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoin

Frequently Asked Questions

What is CWE-639?

CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-639?

There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.

How can I protect against CWE-639 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.

Detect CWE-639 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.

Get Started