SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to b
Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to acce
Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access
SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) v
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference
The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZI
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker t
An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_
Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection p
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing
An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The appl
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users'
The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i
The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to
Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object
CWE-639 Authorization Bypass Through User-Controlled Key
CWE-639 Authorization Bypass Through User-Controlled Key
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i
Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attacke
An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attacke
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions u
The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation
The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due
AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The
Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other proje
An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access
StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenti
Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authentic
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initi
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2
An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attack
Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll ma
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerabil
Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authent
Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract:
AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user p
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started