CWE-639: CWE-639
Yearly Trend
Top Affected Vendors
All CWE-639 CVEs (519)
A vulnerability in Nextcloud's Twofactor WebAuthn plugin allows attackers to remove a user's WebAuthn 2FA device by correctly guessing a long random s...
Dec 5, 2025This vulnerability allows repository administrators in Gogs to delete comments from any repository by manipulating comment IDs, bypassing authorizatio...
Feb 19, 2026This vulnerability in the Timetable and Event Schedule WordPress plugin allows users with Contributor-level permissions to duplicate and view events t...
Dec 3, 2025An Insecure Direct Object Reference vulnerability in Medtronic CareLink Network allows authenticated attackers with specific device and user informati...
Dec 4, 2025This CVE describes an insecure direct object reference (IDOR) vulnerability in WeKan versions before 8.19. Authenticated users can spoof comment autho...
Feb 7, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in WeKan versions before 8.19. Attackers can manipulate checklist identifi...
Feb 7, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in WeKan versions before 8.19. Attackers can manipulate checklist identifi...
Feb 7, 2026This CVE describes an Insecure Direct Object Reference vulnerability in Cloudflare Agents SDK's email routing function. Attackers can spoof email head...
Feb 3, 2026This vulnerability allows authenticated users with normal permissions to modify other users' profile pictures in Askbot. It affects all Askbot version...
Jan 27, 2026An Insecure Direct Object Reference (IDOR) vulnerability in Omada Controllers allows authenticated administrators to manipulate requests and potential...
Jan 26, 2026This vulnerability allows authenticated users to bypass authorization controls in Hubitat Elevation home automation controllers, enabling them to mani...
Jan 22, 2026CVE-2025-4596 is an authorization bypass vulnerability in Asseco ADMX medical records system that allows authenticated users to access other users' me...
Jan 8, 2026This vulnerability allows unauthorized access to sensitive files belonging to other users through an API endpoint. Attackers can access files by guess...
Dec 19, 2025This vulnerability allows unauthorized access to sensitive files belonging to other users through API endpoints. Attackers can access files they shoul...
Dec 19, 2025This vulnerability allows remote attackers to hijack Govee smart devices by binding them to their own accounts through the cloud platform. Attackers g...
Dec 18, 2025This IDOR vulnerability in i2A's CronosWeb allows authenticated attackers to access other users' personal documents by manipulating the documentCode p...
Dec 10, 2025The SolisCloud API has an Insecure Direct Object Reference (IDOR) vulnerability where authenticated users can access detailed data from any solar plan...
Dec 4, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in DeporSite by T-INNOVA. Attackers can manipulate the 'idUsuario' paramet...
Nov 13, 2025Zitadel versions 4.0.0-rc.1 through 4.6.2 contain an insecure direct object reference (IDOR) vulnerability in the V2Beta API. Authenticated users with...
Nov 7, 2025About CWE-639 (CWE-639)
Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.
External reference: View CWE-639 on MITRE CWE →
Monitor CWE-639 Vulnerabilities
Get alerted when new CWE-639 CVEs affect your infrastructure.
Start Monitoring Free