The SolisCloud API suffers from a Broken Access Control vulnerability, specifically an Insecure Direct Object Reference
Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulne
A flaw in the binding process of Govee’s cloud platform and devices allows a remote attacker to bind an existing, online
Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not
An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intende
A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Managemen
A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete
A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or del
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a hig
A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete
A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete
A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress i
Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorr
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the
Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and e
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/accoun
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that o
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnera
The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versio
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in ve
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable
Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete t
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allo
go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - whic
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /c
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to id
ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks a
The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a
A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Pro
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth()
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system sta
Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abus
Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Lim
Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse.
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing att
An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to an
The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Di
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is
The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account take
An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-p
An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to ex
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delet
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started