Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-639

MITRE ↗

CWE-639

174
CRITICAL
645
HIGH
1,343
MEDIUM
96
LOW
2,420 CVEs · Page 30/49
5.3
CVE-2025-25276

An unauthenticated attacker can hijack other users' devices and potentially control them.

5.3
CVE-2025-26857

Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

5.3
CVE-2025-27561

Unauthenticated attackers can rename "rooms" of arbitrary users.

5.3
CVE-2025-27565

An unauthenticated attacker can delete any user's "rooms" by knowing the user's and room IDs.

5.3
CVE-2025-27575

An unauthenticated attacker can obtain EV charger version and firmware upgrading history by knowing the charger ID.

5.3
CVE-2025-27719

Unauthenticated attackers can query an API endpoint and get device details.

5.3
CVE-2025-27927

An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.

5.3
CVE-2025-27929

Unauthenticated attackers can retrieve full list of users associated with arbitrary accounts.

5.3
CVE-2025-30257

Unauthenticated attackers can retrieve serial number of smart meters associated to a specific user account.

5.3
CVE-2025-31147

Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.

5.3
CVE-2025-31654

An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms").

5.3
CVE-2025-31945

An unauthenticated attacker can obtain other users' charger information.

5.3
CVE-2025-31950

An unauthenticated attacker can obtain EV charger energy consumption information of other users.

5.3
CVE-2025-4119

A vulnerability classified as critical was found in Weitong Mall 1.0.0. This vulnerability affects unknown code of the f

5.3
CVE-2025-3889

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version

5.3
CVE-2025-3281

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln

5.3
CVE-2024-8988

The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up

5.3
CVE-2025-3769

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc

5.3
CVE-2025-4691

The Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking plugin for WordPress is vulnerable to I

5.3
CVE-2025-49995

Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments all

5.3
CVE-2025-51533

An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized attackers to access in

5.3
CVE-2025-8755

A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function

5.3
CVE-2025-8794

A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by thi

5.3
CVE-2025-54691

Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors motors-car-dealership-classified-listi

5.3
CVE-2025-8463

Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forcef

5.3
CVE-2025-10493

The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via t

5.3
CVE-2025-10759

A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token

5.3
CVE-2025-7106

danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `c

5.3
CVE-2025-10947

A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is an unknown function of

5.3
CVE-2025-11518

The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver

5.3
CVE-2025-11741

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up t

5.3
CVE-2025-12353

The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for

5.3
CVE-2025-11532

The Wisly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1

5.3
CVE-2025-12427

The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up

5.3
CVE-2025-13389

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthoriz

5.3
CVE-2025-64067

Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles

5.3
CVE-2025-13157

The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions

5.3
CVE-2025-13748

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne

5.3
CVE-2025-63065

Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant media-library-as

5.3
CVE-2025-12883

The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versi

5.3
CVE-2025-66132

Authorization Bypass Through User-Controlled Key vulnerability in FAPI Business s.r.o. FAPI Member fapi-member allows Ex

5.3
CVE-2025-67985

Authorization Bypass Through User-Controlled Key vulnerability in Barn2 Plugins Document Library Lite document-library-l

5.3
CVE-2025-63043

Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid a

5.3
CVE-2025-68979

Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-

5.3
CVE-2025-68997

Authorization Bypass Through User-Controlled Key vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Inc

5.3
CVE-2025-63053

Authorization Bypass Through User-Controlled Key vulnerability in Liton Arefin Master Addons for Elementor master-addons

5.3
CVE-2025-49334

Authorization Bypass Through User-Controlled Key vulnerability in Eduardo Villão MyD Delivery myd-delivery allows Exploi

5.0
CVE-2025-47226

Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.

5.0
CVE-2025-24969

iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts pictur

5.0
CVE-2025-61876

Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an aut

Frequently Asked Questions

What is CWE-639?

CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-639?

There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.

How can I protect against CWE-639 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.

Detect CWE-639 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.

Get Started