Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows all
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 throug
Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rul
A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series products. This vulnerab
A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior t
Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetoo
An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell acc
The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX act
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerabili
Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for
Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/s
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the in
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier
It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid :
Authorization Bypass Through User-Controlled Key vulnerability in UPQODE Whizz.This issue affects Whizzy: from n/a throu
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all vers
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allow
An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentic
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere
In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projec
An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users
An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and includi
MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while sign
Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing on
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows
NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authoriz
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality No
Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti
Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti
A bug in the 9p authentication implementation within lib9p allows an attacker with an existing valid user within the con
An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, inclu
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on c
This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints.
An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. T
Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user is
Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external cl
This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An aut
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerabili
The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and
An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticate
The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Ob
java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users
Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.
Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This all
Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows l
A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started