Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.
An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine wa
Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that w
Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/me
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access r
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access an
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups acce
An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low pri
growi is vulnerable to Authorization Bypass Through User-Controlled Key
Certain HP DesignJet products may be vulnerable to unauthenticated HTTP requests which allow viewing and downloading of
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker
A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or auth
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct
An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object reference
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect r
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related t
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attacker
The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, t
WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify th
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the add
The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object
An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unaut
Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information
The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on end
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.
The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the
Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856d
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint tha
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen acco
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allo
The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on en
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started