CWE-639: CWE-639

519
Total CVEs
63
Critical
165
High
6.6
Avg CVSS

Yearly Trend

2026
89
2025
239
2024
130
2023
28
2022
16

Top Affected Vendors

1 Growatt 12
2 Nextcloud 10
3 Easyappointments 8
4 Liferay 8
5 Boldworkplanner 8
6 Lunary 6
7 Gitlab 6
8 Open Emr 5
9 Wpjobportal 5
10 Apache 4

All CWE-639 CVEs (519)

CVE-2021-40355
8.8

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Siemens Teamcenter PLM software. Attackers can manipulate user-supplied...

Sep 14, 2021
CVE-2020-23722
8.8

FUEL CMS 1.4.7 contains an authorization bypass vulnerability that allows attackers to escalate privileges to super admin level by manipulating 'id' a...

Mar 10, 2021
CVE-2025-14459
8.5

This vulnerability in KubeVirt Containerized Data Importer (CDI) allows authenticated users to clone PersistentVolumeClaims from namespaces they shoul...

Jan 26, 2026
CVE-2025-11690
8.5

An Insecure Direct Object Reference (IDOR) vulnerability in the vehicleId parameter allows attackers to bypass authorization and access sensitive data...

Nov 4, 2025
CVE-2023-38047
8.5

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments scheduling software. It allows low-privileged use...

Jul 9, 2024
CVE-2025-26788
8.4

This vulnerability in StrongKey FIDO Server allows authentication bypass by incorrectly treating non-discoverable credential flows as discoverable tra...

Feb 14, 2025
CVE-2024-42422
8.3

Dell NetWorker versions 19.10 contain an authorization bypass vulnerability where an unauthenticated attacker can manipulate user-controlled keys to a...

Dec 3, 2024
CVE-2024-29194
8.3

This CVE describes an authorization bypass vulnerability in OneUptime where attackers can manipulate client-side stored data to gain administrative pr...

Mar 24, 2024
CVE-2023-4587
8.3

An Insecure Direct Object Reference (IDOR) vulnerability in ZKTeco ZEM800 version 6.60 allows local attackers to access sensitive backup and configura...

Sep 4, 2023
CVE-2025-14844
8.2

This vulnerability allows unauthenticated attackers to access Stripe SetupIntent client_secret values for any membership in the Restrict Content WordP...

Jan 16, 2026
CVE-2024-56143
8.2

This vulnerability in Strapi allows attackers to access private fields like admin passwords and reset tokens by crafting malicious queries with the lo...

Oct 16, 2025
CVE-2023-37871
8.2

This vulnerability allows unauthenticated attackers to bypass authorization in the WooCommerce GoCardless payment gateway plugin by manipulating user-...

Dec 20, 2023
CVE-2026-1375
8.1

This vulnerability allows authenticated attackers with Tutor Instructor-level access or higher to modify or delete arbitrary courses they do not own b...

Feb 3, 2026
CVE-2025-47555
8.1

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Tutor LMS WordPress plugin that allows attackers to bypass authorizatio...

Jan 22, 2026
CVE-2025-41077
8.1

An Insecure Direct Object Reference (IDOR) vulnerability in Viafirma Inbox v4.5.13 allows authenticated users without privileges to list all users, ac...

Jan 12, 2026
CVE-2025-67919
8.1

This vulnerability allows attackers to bypass authorization controls in Woffice Core by manipulating user-controlled keys, potentially accessing unaut...

Jan 8, 2026
CVE-2025-68975
8.1

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Eagle Booking WordPress plugin that allows attackers to bypass auth...

Dec 30, 2025
CVE-2025-68979
8.1

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Google Calendar Events WordPress plugin. Attackers can bypass autho...

Dec 30, 2025
CVE-2025-67909
8.1

This vulnerability allows attackers to bypass authorization controls in WP Swings Membership For WooCommerce by manipulating user-controlled keys, pot...

Dec 24, 2025
CVE-2025-34438
8.1

AVideo versions before 20.1 contain an insecure direct object reference vulnerability that allows authenticated users with upload permissions to modif...

Dec 17, 2025
CVE-2025-58137
8.1

This CVE describes an authorization bypass vulnerability in Apache Fineract where attackers can manipulate user-controlled keys to access unauthorized...

Dec 12, 2025
CVE-2025-61075
8.1

Multiple incorrect access control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow authenticated low-privileged users to perfor...

Dec 9, 2025
CVE-2025-65034
8.1

An improper authorization vulnerability in Rallly allows any authenticated user to reopen finalized polls belonging to other users by manipulating the...

Nov 19, 2025
CVE-2025-56392
8.1

An Insecure Direct Object Reference vulnerability in Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users by manipulating POST requ...

Sep 30, 2025
CVE-2025-43790
8.1

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users to access, creat...

Sep 11, 2025
CVE-2025-52448
8.1

An authorization bypass vulnerability in Salesforce Tableau Server allows attackers to manipulate the validate-initial-sql API modules to gain unautho...

Jul 25, 2025
CVE-2025-25282
8.1

CVE-2025-25282 is an Insecure Direct Object Reference (IDOR) vulnerability in RAGFlow that allows authenticated users to access and modify other tenan...

Feb 21, 2025
CVE-2024-10855
8.1

This vulnerability in the Sirv WordPress plugin allows authenticated attackers with Contributor-level access or higher to delete arbitrary WordPress o...

Nov 20, 2024
CVE-2024-7474
8.1

This IDOR vulnerability in lunary-ai/lunary version 1.3.2 allows authenticated users to view or delete external user accounts by manipulating the 'id'...

Oct 29, 2024
CVE-2024-38447
8.1

CVE-2024-38447 is an Insecure Direct Object Reference vulnerability in NATO NCI ANET 3.4.1 that allows attackers to access private draft reports belon...

Jul 17, 2024
CVE-2024-4151
8.1

An improper access control vulnerability in lunary-ai/lunary version 1.2.2 allows users to view and update any prompts in any projects due to insuffic...

May 20, 2024
CVE-2023-44154
8.1

CVE-2023-44154 is an authorization bypass vulnerability in Acronis Cyber Protect 15 that allows unauthorized users to access and manipulate sensitive ...

Sep 27, 2023
CVE-2023-28656
8.1

CVE-2023-28656 is an authorization bypass vulnerability in NGINX Management Suite that allows authenticated users to access configuration objects outs...

May 3, 2023
CVE-2023-26984
8.1

This vulnerability in Peppermint v0.2.4 allows attackers to bypass authorization and access sensitive email and password data from the Tickets page th...

Mar 29, 2023
CVE-2021-46416
8.1

This vulnerability allows unauthorized user groups to access restricted functionality in SMA SUNNY TRIPOWER 5.0 inverters due to insecure cookie handl...

Apr 7, 2022
CVE-2022-25471
8.1

An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows authenticated attackers to access and modify unauthorized system area...

Mar 3, 2022
CVE-2021-24739
8.1

The Logo Carousel WordPress plugin before version 3.4.2 contains an authorization bypass vulnerability that allows users with Contributor-level permis...

Dec 21, 2021
CVE-2021-39225
8.1

CVE-2021-39225 is an authorization bypass vulnerability in Nextcloud Deck that allows authenticated users to access other users' Deck cards without pr...

Oct 25, 2021
CVE-2025-52446
8.0

An authorization bypass vulnerability in Salesforce Tableau Server allows attackers to manipulate interface parameters and gain unauthorized access to...

Jul 25, 2025
CVE-2025-25777
8.0

This IDOR vulnerability in Codeastro Bus Ticket Booking System v1.0 allows attackers to access other users' profiles by manipulating user IDs in URLs....

Apr 24, 2025
CVE-2024-23112
8.0

This CVE describes an authorization bypass vulnerability in FortiOS and FortiProxy SSL-VPN that allows authenticated attackers to access other users' ...

Mar 12, 2024
CVE-2025-22422
7.8

This vulnerability allows malicious apps to trick Android's authentication system into using one app's approval for another app's privileged operation...

Sep 2, 2025
CVE-2025-2271
7.7

An Insecure Direct Object Reference (IDOR) vulnerability in Issuetrak v17.2.2 and earlier allows low-privileged authenticated users to access audit re...

Mar 13, 2025
CVE-2023-3286
7.7

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments system where a low-privileged user can create add...

Jul 9, 2024
CVE-2023-3289
7.7

This Broken Object Level Authorization (BOLA) vulnerability allows low-privileged users to create services for any user in the system, including admin...

Jul 9, 2024
CVE-2023-3285
7.7

This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments scheduling system. It allows any authenticated lo...

Jul 9, 2024
CVE-2025-13124
7.6

This vulnerability allows attackers to bypass authorization mechanisms in ApplyLogic by manipulating user-controlled keys, potentially gaining unautho...

Dec 11, 2025
CVE-2025-13003
7.6

This vulnerability allows attackers to bypass authorization mechanisms in Aksis AxOnboard software by manipulating user-controlled keys or identifiers...

Dec 11, 2025
CVE-2026-28469
7.5

OpenClaw versions before 2026.2.14 have a webhook routing vulnerability in the Google Chat monitor component that allows attackers to misroute webhook...

Mar 5, 2026
CVE-2026-24773
7.5

CVE-2026-24773 is an Insecure Direct Object Reference (IDOR) vulnerability in Open eClass (formerly GUnet eClass) that allows unauthenticated attacker...

Feb 3, 2026

About CWE-639 (CWE-639)

Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.

External reference: View CWE-639 on MITRE CWE →

Monitor CWE-639 Vulnerabilities

Get alerted when new CWE-639 CVEs affect your infrastructure.

Start Monitoring Free