Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Objec
An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) versio
Authorization Bypass Through User-Controlled Key vulnerability in themeglow JobBoard Job listing job-board-light allows
Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft OctoCloud allows Resource Leak Exposure. Thi
Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft ProKuafor allows Resource Leak Exposure. Thi
Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam Registration allows Exploit
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerab
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to
The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.3
The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi
The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in al
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i
The Typer Core plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.6 vi
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to
Authorization Bypass Through User-Controlled Key vulnerability in NirWp Team Nirweb support nirweb-support.This issue af
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object
The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u
The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to In
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecu
The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref
The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions
The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to
A vulnerability, which was classified as problematic, has been found in SourceCodester Best Employee Management System 1
The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl
A vulnerability has been found in Control iD RH iD 25.2.25.0 and classified as problematic. This vulnerability affects u
SAP Fiori applications using the posting library fail to properly configure security settings during the setup process,
The Manage Bank Statements in SAP S/4HANA allows authenticated attacker to bypass certain functionality restrictions of
The Manage Bank Statements in SAP S/4HANA does not perform required access control checks for an authenticated user to c
The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via
A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows
Authorization Bypass Through User-Controlled Key vulnerability in DevItems Support Genix support-genix-lite allows Explo
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vuln
Authorization Bypass Through User-Controlled Key vulnerability in Scott Taylor Avatar avatar allows Exploiting Incorrect
The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable
A flaw was found in Moodle. This vulnerability allows unauthorized users to access and view RSS feeds due to insufficien
A flaw was found in Moodle. Insufficient capability checks made it possible for a user enrolled in a course to access so
The Homey theme for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.
A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authen
A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform
A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as c
A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5,
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and
Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch wp-jobsearch allows Exploiting Incorr
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenti
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started