CWE-639: CWE-639

519
Total CVEs
63
Critical
165
High
6.6
Avg CVSS

Yearly Trend

2026
89
2025
239
2024
130
2023
28
2022
16

Top Affected Vendors

1 Growatt 12
2 Nextcloud 10
3 Easyappointments 8
4 Liferay 8
5 Boldworkplanner 8
6 Lunary 6
7 Gitlab 6
8 Open Emr 5
9 Wpjobportal 5
10 Apache 4

All CWE-639 CVEs (519)

CVE-2025-66558
3.1

A vulnerability in Nextcloud's Twofactor WebAuthn plugin allows attackers to remove a user's WebAuthn 2FA device by correctly guessing a long random s...

Dec 5, 2025
CVE-2026-25120
2.7

This vulnerability allows repository administrators in Gogs to delete comments from any repository by manipulating comment IDs, bypassing authorizatio...

Feb 19, 2026
CVE-2025-12954
2.7

This vulnerability in the Timetable and Event Schedule WordPress plugin allows users with Contributor-level permissions to duplicate and view events t...

Dec 3, 2025
CVE-2025-12997
2.2

An Insecure Direct Object Reference vulnerability in Medtronic CareLink Network allows authenticated attackers with specific device and user informati...

Dec 4, 2025
CVE-2026-25567
N/A

This CVE describes an insecure direct object reference (IDOR) vulnerability in WeKan versions before 8.19. Authenticated users can spoof comment autho...

Feb 7, 2026
CVE-2026-25563
N/A

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in WeKan versions before 8.19. Attackers can manipulate checklist identifi...

Feb 7, 2026
CVE-2026-25564
N/A

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in WeKan versions before 8.19. Attackers can manipulate checklist identifi...

Feb 7, 2026
CVE-2026-1664
N/A

This CVE describes an Insecure Direct Object Reference vulnerability in Cloudflare Agents SDK's email routing function. Attackers can spoof email head...

Feb 3, 2026
CVE-2026-1213
N/A

This vulnerability allows authenticated users with normal permissions to modify other users' profile pictures in Askbot. It affects all Askbot version...

Jan 27, 2026
CVE-2025-9520
N/A

An Insecure Direct Object Reference (IDOR) vulnerability in Omada Controllers allows authenticated administrators to manipulate requests and potential...

Jan 26, 2026
CVE-2026-1201
N/A

This vulnerability allows authenticated users to bypass authorization controls in Hubitat Elevation home automation controllers, enabling them to mani...

Jan 22, 2026
CVE-2025-4596
N/A

CVE-2025-4596 is an authorization bypass vulnerability in Asseco ADMX medical records system that allows authenticated users to access other users' me...

Jan 8, 2026
CVE-2025-14882
N/A

This vulnerability allows unauthorized access to sensitive files belonging to other users through an API endpoint. Attackers can access files by guess...

Dec 19, 2025
CVE-2025-14881
N/A

This vulnerability allows unauthorized access to sensitive files belonging to other users through API endpoints. Attackers can access files they shoul...

Dec 19, 2025
CVE-2025-10910
N/A

This vulnerability allows remote attackers to hijack Govee smart devices by binding them to their own accounts through the cloud platform. Attackers g...

Dec 18, 2025
CVE-2025-41358
N/A

This IDOR vulnerability in i2A's CronosWeb allows authenticated attackers to access other users' personal documents by manipulating the documentCode p...

Dec 10, 2025
CVE-2025-13932
N/A

The SolisCloud API has an Insecure Direct Object Reference (IDOR) vulnerability where authenticated users can access detailed data from any solar plan...

Dec 4, 2025
CVE-2025-41069
N/A

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in DeporSite by T-INNOVA. Attackers can manipulate the 'idUsuario' paramet...

Nov 13, 2025
CVE-2025-64431
N/A

Zitadel versions 4.0.0-rc.1 through 4.6.2 contain an insecure direct object reference (IDOR) vulnerability in the V2Beta API. Authenticated users with...

Nov 7, 2025

About CWE-639 (CWE-639)

Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.

External reference: View CWE-639 on MITRE CWE →

Monitor CWE-639 Vulnerabilities

Get alerted when new CWE-639 CVEs affect your infrastructure.

Start Monitoring Free