A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the syste
OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation o
Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unaut
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPer
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, withi
An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any p
NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft rep
In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view o
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.
A BOLA vulnerability in POST /appointments allows a low privileged user to create an appointment for any user in the sys
A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in th
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (incl
An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R
Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate
SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner m
An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attac
An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unaut
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This is
The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (I
Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for Wo
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary fil
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive informatio
SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive infor
IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to
IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to
Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID paramete
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows una
Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Ch
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allow
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub all
Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrec
An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Sec
An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of
Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Manage
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality No
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients
An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This
Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerabil
A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this
A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0.
A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This
A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vu
A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown proc
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create
HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference (IDOR) vulnerability. A user can obtain certai
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started