Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated rem
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issu
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verifica
An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the a
Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treat
Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows s
n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configure
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any reposit
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and
Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envan
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/Pa
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
A vulnerability was detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This impacts an unkn
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to
CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, a
Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify
IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The
Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulne
teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studi
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Ob
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users end
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation
A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a use
TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authent
Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.
OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidate
TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability thro
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso
gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who h
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0
OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran
ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the fam
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2,
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started