Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-639

MITRE ↗

CWE-639

174
CRITICAL
645
HIGH
1,343
MEDIUM
96
LOW
2,420 CVEs · Page 29/49
6.5
CVE-2025-69202

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream servi

6.4
CVE-2025-8532

Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade

6.3
CVE-2024-11146

TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-

6.3
CVE-2025-6765

A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects s

6.3
CVE-2025-0642

Use of Hard-coded Credentials, Authorization Bypass Through User-Controlled Key vulnerability in PosCube Hardware Softwa

6.3
CVE-2025-66551

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious use

6.3
CVE-2025-15106

A weakness has been identified in getmaxun maxun up to 0.0.28. The affected element is the function router.get of the fi

6.1
CVE-2025-8887

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unautho

6.0
CVE-2025-0606

Authorization Bypass Through User-Controlled Key vulnerability in Logo Software Inc. Logo Cloud allows Forceful Browsing

5.5
CVE-2024-13175

Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. T

5.5
CVE-2025-59562

Authorization Bypass Through User-Controlled Key vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Inco

5.5
CVE-2025-8884

Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Pri

5.4
CVE-2024-44450

Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.

5.4
CVE-2024-13692

The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature

5.4
CVE-2025-31867

Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Job Manager js-jobs allows Exploiting Incor

5.4
CVE-2025-6329

A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue

5.4
CVE-2025-7947

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /

5.4
CVE-2025-51479

Authorization bypass in update_user_group in onyx-dot-app Onyx Enterprise Edition 0.27.0 allows remote authenticated att

5.4
CVE-2025-53357

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that

5.4
CVE-2025-9264

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src

5.4
CVE-2025-57886

Authorization Bypass Through User-Controlled Key vulnerability in Equalize Digital Accessibility Checker by Equalize Dig

5.4
CVE-2025-57994

Authorization Bypass Through User-Controlled Key vulnerability in Sayful Islam Upcoming Events Lists upcoming-events-lis

5.4
CVE-2025-12126

The The Total Book Project plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,

5.4
CVE-2025-63291

When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify

5.4
CVE-2025-12524

The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inc

5.4
CVE-2025-12881

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in

5.4
CVE-2025-69029

Authorization Bypass Through User-Controlled Key vulnerability in Select-Themes Struktur struktur allows Exploiting Inco

5.4
CVE-2025-69030

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allow

5.4
CVE-2025-69032

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Inco

5.3
CVE-2024-13457

The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version

5.3
CVE-2024-13372

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to

5.3
CVE-2024-13428

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to

5.3
CVE-2024-13719

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up

5.3
CVE-2025-26965

Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting I

5.3
CVE-2024-10925

A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 1

5.3
CVE-2024-13887

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Di

5.3
CVE-2024-11167

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to

5.3
CVE-2025-3282

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln

5.3
CVE-2025-3537

A vulnerability was found in Tutorials-Website Employee Management System 1.0. It has been classified as critical. This

5.3
CVE-2025-24487

An unauthenticated attacker can infer the existence of usernames in the system by querying an API.

5.3
CVE-2025-27568

An unauthenticated attacker can get users' emails by knowing usernames. A password reset email will be sent in response

5.3
CVE-2025-27938

Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "rooms").

5.3
CVE-2025-30254

An unauthenticated attacker can obtain a serial number of a smart meter(s) using its owner's username.

5.3
CVE-2025-30514

Unauthenticated attackers can obtain restricted information about a user's smart device collections (i.e., "scenes").

5.3
CVE-2025-31357

An unauthenticated attacker can obtain a user's plant list by knowing the username.

5.3
CVE-2025-31933

An unauthenticated attacker can check the existence of usernames in the system by querying an API.

5.3
CVE-2025-31941

An unauthenticated attacker can obtain a list of smart devices by knowing a valid username.

5.3
CVE-2025-31949

An authenticated attacker can obtain any plant name by knowing the plant ID.

5.3
CVE-2025-24315

Unauthenticated attackers can add devices of other users to their scenes (or arbitrary scenes of other arbitrary users).

5.3
CVE-2025-24850

An attacker can export other users' plant information.

Frequently Asked Questions

What is CWE-639?

CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-639?

There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.

How can I protect against CWE-639 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.

Detect CWE-639 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.

Get Started