CWE-639: CWE-639

517
Total CVEs
63
Critical
163
High
6.6
Avg CVSS

Yearly Trend

2026
88
2025
239
2024
130
2023
28
2022
16

Top Affected Vendors

1 Growatt 12
2 Nextcloud 10
3 Easyappointments 8
4 Liferay 8
5 Boldworkplanner 8
6 Lunary 6
7 Gitlab 6
8 Open Emr 5
9 Wpjobportal 5
10 Apache 4

All CWE-639 CVEs (517)

CVE-2025-40805
10.0

This critical vulnerability allows unauthenticated remote attackers to bypass authentication on specific API endpoints and impersonate legitimate user...

Jan 13, 2026
CVE-2024-45032
10.0

This critical vulnerability allows unauthenticated remote attackers to impersonate legitimate devices in Siemens Industrial Edge Management systems by...

Sep 10, 2024
CVE-2025-0987
9.9

CVE-2025-0987 is an authorization bypass vulnerability in CB Project Ltd. Co. CVLand software that allows attackers to manipulate parameters and gain ...

Nov 3, 2025
CVE-2023-3287
9.9

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments scheduling software. It allows low-privileged use...

Jul 9, 2024
CVE-2023-38052
9.9

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in Easy!Appointments that allows low-privileged users to access, modify, o...

Jul 9, 2024
CVE-2023-38054
9.9

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in Easy!Appointments where low-privileged users can access, modify, or del...

Jul 9, 2024
CVE-2023-38048
9.9

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in Easy!Appointments that allows low-privileged users to access, modify, o...

Jul 9, 2024
CVE-2020-37094
9.8

EspoCRM 5.8.5 contains an authentication bypass vulnerability that allows attackers to access other user accounts by manipulating authorization header...

Feb 3, 2026
CVE-2025-15521
9.8

This vulnerability allows unauthenticated attackers to change any user's password in the Academy LMS WordPress plugin, including administrator account...

Jan 21, 2026
CVE-2026-22234
9.8

This vulnerability allows unauthenticated attackers to access the OPEXUS eCasePortal 'Attachments.aspx' endpoint, manipulate predictable 'formid' valu...

Jan 8, 2026
CVE-2025-15018
9.8

The Optional Email WordPress plugin contains a privilege escalation vulnerability that allows unauthenticated attackers to reset any user's password, ...

Jan 7, 2026
CVE-2025-14998
9.8

The Branda WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to reset passwords for any user account, ...

Jan 2, 2026
CVE-2023-53955
9.8

This CVE describes an insecure direct object reference vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x systems that allows attackers to bypass aut...

Dec 22, 2025
CVE-2023-53914
9.8

CVE-2023-53914 is an authentication bypass vulnerability in UliCMS 2023.1 that allows unauthenticated attackers to create administrative accounts with...

Dec 17, 2025
CVE-2025-67165
9.8

An Insecure Direct Object Reference (IDOR) vulnerability in Pagekit CMS v1.0.18 allows attackers to manipulate object references (like user IDs) to es...

Dec 17, 2025
CVE-2025-13615
9.8

This vulnerability in the StreamTube Core WordPress plugin allows unauthenticated attackers to change user passwords, including administrator accounts...

Nov 30, 2025
CVE-2025-58627
9.8

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Miraculous Core WordPress plugin that allows attackers to bypass au...

Nov 6, 2025
CVE-2025-10742
9.8

The Truelysell Core WordPress plugin allows unauthenticated attackers to change user passwords, including administrator accounts, through an authoriza...

Oct 16, 2025
CVE-2025-5948
9.8

The Service Finder Bookings WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to take over any user ac...

Sep 19, 2025
CVE-2025-45968
9.8

System PDV v1.0 contains an Insecure Direct Object Reference (IDOR) vulnerability that allows remote attackers to access sensitive information by mani...

Aug 25, 2025
CVE-2025-5947
9.8

The Service Finder Bookings WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, i...

Aug 1, 2025
CVE-2025-3810
9.8

The WPBookit WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to change any user's email and password...

May 9, 2025
CVE-2024-11284
9.8

The WP JobHunt WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to reset any user's password, includi...

Mar 14, 2025
CVE-2024-10215
9.8

The WPBookit WordPress plugin vulnerability allows unauthenticated attackers to change any user's password, including administrators, by bypassing aut...

Jan 9, 2025
CVE-2024-50483
9.8

This vulnerability allows attackers to bypass authorization controls in the WordPress Meetup plugin by manipulating user-controlled keys, potentially ...

Oct 28, 2024
CVE-2024-9263
9.8

This vulnerability allows unauthenticated attackers to reset emails and passwords of any user account in the WP Timetics plugin, including administrat...

Oct 17, 2024
CVE-2024-9862
9.8

This vulnerability allows unauthenticated attackers to change any WordPress user's password, including administrators, without knowing the current pas...

Oct 17, 2024
CVE-2024-8485
9.8

The REST API TO MiniProgram WordPress plugin has a critical privilege escalation vulnerability that allows unauthenticated attackers to update any use...

Sep 25, 2024
CVE-2024-8292
9.8

The WP-Recall plugin for WordPress has a critical vulnerability that allows unauthenticated attackers to reset any user's password by supplying their ...

Sep 6, 2024
CVE-2024-27730
9.8

This vulnerability allows remote attackers to bypass authorization checks in Friendica's calendar event feature, potentially accessing sensitive infor...

Aug 15, 2024
CVE-2024-39223
9.8

This CVE describes an authentication bypass vulnerability in the SSH service of gost v2.11.5. Attackers can intercept communications by setting the Ho...

Jul 3, 2024
CVE-2024-1107
9.8

This CVE describes an authorization bypass vulnerability in Talya Informatics Travel APPS where attackers can manipulate user-controlled keys to acces...

Jun 27, 2024
CVE-2023-43668
9.8

CVE-2023-43668 is an authorization bypass vulnerability in Apache InLong that allows attackers to manipulate user-controlled parameters to bypass secu...

Oct 16, 2023
CVE-2023-2958
9.8

CVE-2023-2958 is an authorization bypass vulnerability in Origin Software ATS Pro that allows attackers to bypass authentication mechanisms by manipul...

Jul 17, 2023
CVE-2023-37242
9.8

This vulnerability allows attackers to intercept modem commands in the atcmdserver module on affected Huawei devices. Attackers can exploit this to re...

Jul 6, 2023
CVE-2023-2276
9.8

This vulnerability allows unauthenticated attackers to bypass authorization in the WCFM Membership plugin for WordPress, enabling them to change user ...

May 20, 2023
CVE-2022-30495
9.8

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in oretnom23 Automotive Shop Management System v1.0 that allows attackers ...

May 26, 2022
CVE-2022-0691
9.8

CVE-2022-0691 is an authorization bypass vulnerability in the url-parse npm package where attackers can manipulate URL parsing to bypass authorization...

Feb 21, 2022
CVE-2022-22832
9.8

CVE-2022-22832 is an authorization bypass vulnerability in Servisnet Tessa where unauthenticated users can access sensitive user data via the /data-se...

Feb 6, 2022
CVE-2021-45428
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files (including HTML and CGI scripts) to the TLR-2005KSH device via the enabl...

Jan 3, 2022
CVE-2021-44949
9.8

CVE-2021-44949 is an access control vulnerability in glFusion CMS that allows unauthorized access to user management functions via the /public_html/us...

Dec 14, 2021
CVE-2021-37184
9.8

An unauthenticated attacker can change any user's password in Siemens Industrial Edge Management systems, allowing impersonation of valid users. This ...

Sep 14, 2021
CVE-2021-32744
9.8

CVE-2021-32744 is an Insecure Direct Object Reference (IDOR) vulnerability in Collabora Online that allows unauthenticated attackers to access files c...

Jul 21, 2021
CVE-2026-24379
9.1

This CVE describes an authorization bypass vulnerability in the WP Job Portal WordPress plugin where attackers can manipulate user-controlled keys to ...

Jan 22, 2026
CVE-2024-50685
9.1

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in SunGrow iSolarCloud's powerStationService API model. Attackers can mani...

Feb 26, 2025
CVE-2024-50687
9.1

SunGrow iSolarCloud versions before October 31, 2024 contain an insecure direct object reference (IDOR) vulnerability in the devService API model. Thi...

Feb 26, 2025
CVE-2024-50689
9.1

This vulnerability allows attackers to bypass authorization and access unauthorized organizational data through the orgService API in SunGrow iSolarCl...

Feb 26, 2025
CVE-2024-50693
9.1

This vulnerability allows attackers to bypass authorization controls in SunGrow iSolarCloud's userService API, enabling unauthorized access to other u...

Feb 26, 2025
CVE-2025-1270
9.1

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Anapi Group's h6web software that allows authenticated attackers to acc...

Feb 13, 2025
CVE-2024-49388
9.1

CVE-2024-49388 is an authorization bypass vulnerability in Acronis Cyber Protect 16 that allows attackers to manipulate sensitive information without ...

Oct 15, 2024

About CWE-639 (CWE-639)

Our database tracks 517 CVEs classified as CWE-639, with 63 rated critical and 163 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.

External reference: View CWE-639 on MITRE CWE →

Monitor CWE-639 Vulnerabilities

Get alerted when new CWE-639 CVEs affect your infrastructure.

Start Monitoring Free