CWE-639: CWE-639
Yearly Trend
Top Affected Vendors
All CWE-639 CVEs (519)
This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Siemens Teamcenter PLM software. Attackers can manipulate user-supplied...
Sep 14, 2021FUEL CMS 1.4.7 contains an authorization bypass vulnerability that allows attackers to escalate privileges to super admin level by manipulating 'id' a...
Mar 10, 2021This vulnerability in KubeVirt Containerized Data Importer (CDI) allows authenticated users to clone PersistentVolumeClaims from namespaces they shoul...
Jan 26, 2026An Insecure Direct Object Reference (IDOR) vulnerability in the vehicleId parameter allows attackers to bypass authorization and access sensitive data...
Nov 4, 2025This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments scheduling software. It allows low-privileged use...
Jul 9, 2024This vulnerability in StrongKey FIDO Server allows authentication bypass by incorrectly treating non-discoverable credential flows as discoverable tra...
Feb 14, 2025Dell NetWorker versions 19.10 contain an authorization bypass vulnerability where an unauthenticated attacker can manipulate user-controlled keys to a...
Dec 3, 2024This CVE describes an authorization bypass vulnerability in OneUptime where attackers can manipulate client-side stored data to gain administrative pr...
Mar 24, 2024An Insecure Direct Object Reference (IDOR) vulnerability in ZKTeco ZEM800 version 6.60 allows local attackers to access sensitive backup and configura...
Sep 4, 2023This vulnerability allows unauthenticated attackers to access Stripe SetupIntent client_secret values for any membership in the Restrict Content WordP...
Jan 16, 2026This vulnerability in Strapi allows attackers to access private fields like admin passwords and reset tokens by crafting malicious queries with the lo...
Oct 16, 2025This vulnerability allows unauthenticated attackers to bypass authorization in the WooCommerce GoCardless payment gateway plugin by manipulating user-...
Dec 20, 2023This vulnerability allows authenticated attackers with Tutor Instructor-level access or higher to modify or delete arbitrary courses they do not own b...
Feb 3, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Tutor LMS WordPress plugin that allows attackers to bypass authorizatio...
Jan 22, 2026An Insecure Direct Object Reference (IDOR) vulnerability in Viafirma Inbox v4.5.13 allows authenticated users without privileges to list all users, ac...
Jan 12, 2026This vulnerability allows attackers to bypass authorization controls in Woffice Core by manipulating user-controlled keys, potentially accessing unaut...
Jan 8, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Eagle Booking WordPress plugin that allows attackers to bypass auth...
Dec 30, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Google Calendar Events WordPress plugin. Attackers can bypass autho...
Dec 30, 2025This vulnerability allows attackers to bypass authorization controls in WP Swings Membership For WooCommerce by manipulating user-controlled keys, pot...
Dec 24, 2025AVideo versions before 20.1 contain an insecure direct object reference vulnerability that allows authenticated users with upload permissions to modif...
Dec 17, 2025This CVE describes an authorization bypass vulnerability in Apache Fineract where attackers can manipulate user-controlled keys to access unauthorized...
Dec 12, 2025Multiple incorrect access control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow authenticated low-privileged users to perfor...
Dec 9, 2025An improper authorization vulnerability in Rallly allows any authenticated user to reopen finalized polls belonging to other users by manipulating the...
Nov 19, 2025An Insecure Direct Object Reference vulnerability in Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users by manipulating POST requ...
Sep 30, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users to access, creat...
Sep 11, 2025An authorization bypass vulnerability in Salesforce Tableau Server allows attackers to manipulate the validate-initial-sql API modules to gain unautho...
Jul 25, 2025CVE-2025-25282 is an Insecure Direct Object Reference (IDOR) vulnerability in RAGFlow that allows authenticated users to access and modify other tenan...
Feb 21, 2025This vulnerability in the Sirv WordPress plugin allows authenticated attackers with Contributor-level access or higher to delete arbitrary WordPress o...
Nov 20, 2024This IDOR vulnerability in lunary-ai/lunary version 1.3.2 allows authenticated users to view or delete external user accounts by manipulating the 'id'...
Oct 29, 2024CVE-2024-38447 is an Insecure Direct Object Reference vulnerability in NATO NCI ANET 3.4.1 that allows attackers to access private draft reports belon...
Jul 17, 2024An improper access control vulnerability in lunary-ai/lunary version 1.2.2 allows users to view and update any prompts in any projects due to insuffic...
May 20, 2024CVE-2023-44154 is an authorization bypass vulnerability in Acronis Cyber Protect 15 that allows unauthorized users to access and manipulate sensitive ...
Sep 27, 2023CVE-2023-28656 is an authorization bypass vulnerability in NGINX Management Suite that allows authenticated users to access configuration objects outs...
May 3, 2023This vulnerability in Peppermint v0.2.4 allows attackers to bypass authorization and access sensitive email and password data from the Tickets page th...
Mar 29, 2023This vulnerability allows unauthorized user groups to access restricted functionality in SMA SUNNY TRIPOWER 5.0 inverters due to insecure cookie handl...
Apr 7, 2022An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows authenticated attackers to access and modify unauthorized system area...
Mar 3, 2022The Logo Carousel WordPress plugin before version 3.4.2 contains an authorization bypass vulnerability that allows users with Contributor-level permis...
Dec 21, 2021CVE-2021-39225 is an authorization bypass vulnerability in Nextcloud Deck that allows authenticated users to access other users' Deck cards without pr...
Oct 25, 2021An authorization bypass vulnerability in Salesforce Tableau Server allows attackers to manipulate interface parameters and gain unauthorized access to...
Jul 25, 2025This IDOR vulnerability in Codeastro Bus Ticket Booking System v1.0 allows attackers to access other users' profiles by manipulating user IDs in URLs....
Apr 24, 2025This CVE describes an authorization bypass vulnerability in FortiOS and FortiProxy SSL-VPN that allows authenticated attackers to access other users' ...
Mar 12, 2024This vulnerability allows malicious apps to trick Android's authentication system into using one app's approval for another app's privileged operation...
Sep 2, 2025An Insecure Direct Object Reference (IDOR) vulnerability in Issuetrak v17.2.2 and earlier allows low-privileged authenticated users to access audit re...
Mar 13, 2025This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments system where a low-privileged user can create add...
Jul 9, 2024This Broken Object Level Authorization (BOLA) vulnerability allows low-privileged users to create services for any user in the system, including admin...
Jul 9, 2024This CVE describes a Broken Object Level Authorization (BOLA) vulnerability in the Easy!Appointments scheduling system. It allows any authenticated lo...
Jul 9, 2024This vulnerability allows attackers to bypass authorization mechanisms in ApplyLogic by manipulating user-controlled keys, potentially gaining unautho...
Dec 11, 2025This vulnerability allows attackers to bypass authorization mechanisms in Aksis AxOnboard software by manipulating user-controlled keys or identifiers...
Dec 11, 2025OpenClaw versions before 2026.2.14 have a webhook routing vulnerability in the Google Chat monitor component that allows attackers to misroute webhook...
Mar 5, 2026CVE-2026-24773 is an Insecure Direct Object Reference (IDOR) vulnerability in Open eClass (formerly GUnet eClass) that allows unauthenticated attacker...
Feb 3, 2026About CWE-639 (CWE-639)
Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.
External reference: View CWE-639 on MITRE CWE →
Monitor CWE-639 Vulnerabilities
Get alerted when new CWE-639 CVEs affect your infrastructure.
Start Monitoring Free