DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolu
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id}
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.j
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API auth
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u
In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain perm
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, r
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutatio
Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploita
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify o
InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user c
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, auth
Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization
Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, whi
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* In
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allo
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator b
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability ch
Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any aut
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users'
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up
The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impe
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 1
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verif
Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a cli
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confir
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthori
IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* ac
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.
The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu
An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and
Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (I
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 1,321 CVE records associated with CWE-639 in our database. Of these, 86 are critical severity, 358 are high severity, and 663 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started