A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulner
An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single
Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.
Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or v
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access controls for channel a
Insecure handling of ssh keys used to bootstrap clients allows local attackers to potentially gain access to the keys
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic
Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may a
Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrar
An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and belo
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management Syste
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid :
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Insecure Direct Obje
IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypa
OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Refer
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown functio
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue aff
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference
Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermedi
An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 throug
The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthentica
The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retr
The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl
The Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form plugin fo
Authorization Bypass Through User-Controlled Key vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs
Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimat
Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP Rating System.This issue
Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects S
The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verificati
A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the
Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoic
An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the
The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and in
aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.
The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure D
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerab
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i
The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Referen
The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Expos
A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the s
An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.
The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially r
A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via upl
JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker
JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started