Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnera
Authorization Bypass Through User-Controlled Key vulnerability in Origin Software ATS Pro allows Authentication Abuse, A
Authorization Bypass Through User-Controlled Key vulnerability in Apache InLong.This issue affects Apache InLong: from 1
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save U
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Ac
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication i
Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any use
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to
Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Aut
Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authe
Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authent
Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authenticati
An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in th
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up
Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker to change the password
The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and includi
An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any
SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super adm
The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions u
Authorization Bypass Through User-Controlled Key vulnerability in Usta AYBS allows Authentication Abuse, Authentication
The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has suffi
Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possib
Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV genera
An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data
In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaite
An IDOR vulnerability has been found in ZKTeco ZEM800 product affecting version 6.60. This vulnerability allows a local
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susc
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless:
The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and
An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assi
EasyTor Applications – Authorization Bypass - EasyTor Applications may allow authorization bypass via unspecified meth
DataEase is an open source data visualization and analysis tool. The API interface for DataEase delete dashboard and del
Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low-privileged user to impersonat
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Ac
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooC
In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass of Parcel Mismatch mitig
The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a
Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Authentication Bypass. The program uses a fixed JWT key, and the stored
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x befor
An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Atta
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started