CWE-639: CWE-639

519
Total CVEs
63
Critical
165
High
6.6
Avg CVSS

Yearly Trend

2026
89
2025
239
2024
130
2023
28
2022
16

Top Affected Vendors

1 Growatt 12
2 Nextcloud 10
3 Easyappointments 8
4 Liferay 8
5 Boldworkplanner 8
6 Lunary 6
7 Gitlab 6
8 Open Emr 5
9 Wpjobportal 5
10 Apache 4

All CWE-639 CVEs (519)

CVE-2021-41305
7.5

This vulnerability allows anonymous remote attackers to view private project and filter names in Atlassian Jira Server and Data Center via an Insecure...

Oct 26, 2021
CVE-2021-41307
7.5

This vulnerability allows unauthenticated remote attackers to view names of private projects and filters in Atlassian Jira Server and Data Center via ...

Oct 26, 2021
CVE-2021-36388
7.5

This vulnerability allows attackers to enumerate and download user profile pictures in Yellowfin BI software through an Insecure Direct Object Referen...

Oct 14, 2021
CVE-2021-37628
7.5

This vulnerability in Nextcloud Richdocuments allows attackers to bypass 'Upload Only' file drop restrictions and read arbitrary files from public lin...

Sep 7, 2021
CVE-2021-24562
7.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the LifterLMS WordPress plugin. It allows authenticated students to acc...

Aug 23, 2021
CVE-2025-68051
7.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Shiprocket WordPress plugin that allows attackers to bypass authori...

Feb 20, 2026
CVE-2025-9062
7.3

This vulnerability allows attackers to bypass authorization controls in MeCODE Informatics and Engineering Services Ltd. Envanty software by manipulat...

Feb 19, 2026
CVE-2024-10174
7.3

The WP Project Manager plugin for WordPress has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to impersonate...

Nov 13, 2024
CVE-2024-10121
7.3

This critical vulnerability in wfh45678 Radar allows remote attackers to bypass authentication by manipulating the Interface Handler component with /....

Oct 18, 2024
CVE-2024-2577
7.3

This CVE describes an authorization bypass vulnerability in SourceCodester Employee Task Management System 1.0. Attackers can manipulate the admin_id ...

Mar 18, 2024
CVE-2024-2575
7.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in SourceCodester Employee Task Management System 1.0. Attackers can bypas...

Mar 18, 2024
CVE-2024-0264
7.3

This vulnerability allows remote attackers to bypass authentication in SourceCodester Clinic Queuing System 1.0 by manipulating the formToken argument...

Jan 7, 2024
CVE-2022-0624
7.3

This vulnerability allows attackers to bypass authorization controls by manipulating user-controlled keys in the parse-path library. It affects applic...

Jun 28, 2022
CVE-2021-44160
7.3

CVE-2021-44160 allows remote attackers to bypass authentication in Carinal Tien Hospital Health Report System by modifying cookie parameters. This ena...

Dec 29, 2021
CVE-2023-6317
7.2

This vulnerability allows attackers to bypass the security PIN prompt in the secondscreen.gateway service on affected LG webOS smart TVs. Attackers ca...

Apr 9, 2024
CVE-2021-22023
7.2

This vulnerability allows an attacker with administrative API access to vRealize Operations Manager to modify other users' information, potentially le...

Aug 30, 2021
CVE-2026-23843
7.1

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the teklifolustur_app PHP application. Authenticated users can manipula...

Jan 19, 2026
CVE-2025-14101
7.1

This vulnerability allows attackers to bypass authorization controls in PaperWork by manipulating user-controlled keys or identifiers. It affects all ...

Dec 17, 2025
CVE-2025-4040
7.1

An authorization bypass vulnerability in Turpak Automatic Station Monitoring System allows attackers to escalate privileges by manipulating user-contr...

Jul 21, 2025
CVE-2024-42169
7.1

This vulnerability in HCL MyXalytics allows attackers to access unauthorized data due to missing access control checks. It affects users of HCL MyXaly...

Jan 11, 2025
CVE-2024-45606
7.1

This vulnerability allows authenticated Sentry users to mute alert rules from organizations and projects they don't belong to or have permissions for....

Sep 17, 2024
CVE-2023-40720
7.1

This vulnerability allows authenticated attackers to bypass authorization controls and access other users' SIP configuration data on FortiVoiceEnterpr...

May 14, 2024
CVE-2024-1470
7.1

This vulnerability allows attackers to bypass authorization controls in NetIQ Client Login Extension on Windows by manipulating user-controlled keys, ...

Feb 29, 2024
CVE-2023-50342
7.1

HCL DRYiCE MyXalytics has an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to access other users' information ...

Jan 3, 2024
CVE-2023-1750
7.1

Nexx Smart Home devices have an access control vulnerability that allows attackers with a valid device ID to access sensitive device information, modi...

Apr 4, 2023
CVE-2022-34150
7.1

The MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability that allows authenticated users to access...

Jul 20, 2022
CVE-2022-22331
7.1

CVE-2022-22331 is an Insecure Direct Object Reference (IDOR) vulnerability in IBM Sterling Partner Engagement Manager 6.2.0 that allows authenticated ...

Apr 1, 2022
CVE-2021-36874
7.1

This vulnerability allows authenticated WordPress users to access or modify data belonging to other users through insecure direct object references in...

Sep 27, 2021
CVE-2025-36365
6.8

This CVE describes an authorization bypass vulnerability in IBM Db2 where authenticated users can execute unauthorized commands by exploiting cataloge...

Jan 30, 2026
CVE-2025-12351
6.8

Honeywell S35 Series Cameras have an authorization bypass vulnerability in the user controller key that allows attackers to escalate privileges to adm...

Oct 27, 2025
CVE-2024-13063
6.8

This vulnerability allows attackers to bypass authorization controls in Akinsoft MyRezzta by manipulating user-controlled keys, enabling forceful brow...

Sep 3, 2025
CVE-2021-37577
6.8

This Bluetooth vulnerability allows an unauthenticated attacker to perform a man-in-the-middle attack during pairing to discover the passkey. It affec...

Oct 1, 2024
CVE-2024-3035
6.8

A permission check vulnerability in GitLab CE/EE allows LFS (Large File Storage) tokens to read and write to user-owned repositories without proper au...

Aug 8, 2024
CVE-2024-47495
6.7

An authorization bypass vulnerability in Juniper Junos OS Evolved allows locally authenticated attackers with shell access to gain full device control...

Oct 11, 2024
CVE-2026-27943
6.5

OpenEMR versions up to 8.0.0 contain an authorization bypass vulnerability in the eye exam module. Authenticated users can access or modify any patien...

Feb 26, 2026
CVE-2026-25929
6.5

This vulnerability in OpenEMR allows authenticated users with document access control to bypass authorization checks and view other patients' photos b...

Feb 25, 2026
CVE-2026-25220
6.5

This vulnerability in OpenEMR allows any authenticated user to view all internal messages in the Message Center by accessing messages.php?show_all=yes...

Feb 25, 2026
CVE-2026-2698
6.5

This CVE describes an improper access control vulnerability where authenticated users can access resources beyond their authorized permissions. It aff...

Feb 23, 2026
CVE-2025-68514
6.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Paid Member Subscriptions WordPress plugin. Attackers can bypass au...

Feb 20, 2026
CVE-2025-70063
6.5

This IDOR vulnerability in PHPGurukul Hospital Management System allows authenticated users to access other patients' confidential medical records by ...

Feb 18, 2026
CVE-2026-1436
6.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Graylog API version 2.2.3 where authenticated users can modify user IDs...

Feb 18, 2026
CVE-2026-24900
6.5

MarkUs versions before 2.9.1 contain an authorization bypass vulnerability where users can access arbitrary student submission files by manipulating t...

Feb 9, 2026
CVE-2026-24134
6.5

StudioCMS versions before 0.2.0 contain a Broken Object Level Authorization vulnerability that allows users with the 'Visitor' role to access draft co...

Jan 28, 2026
CVE-2025-10019
6.5

This CVE describes an authorization bypass vulnerability in the Contact Form Email WordPress plugin where attackers can access or manipulate data by c...

Dec 18, 2025
CVE-2025-34435
6.5

AVideo versions before 20.1 contain an insecure direct object reference (IDOR) vulnerability that allows any authenticated user to delete media files ...

Dec 17, 2025
CVE-2025-68071
6.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Essential Real Estate WordPress plugin that allows attackers to byp...

Dec 16, 2025
CVE-2025-66132
6.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the FAPI Member WordPress plugin that allows attackers to bypass author...

Dec 16, 2025
CVE-2025-64497
6.5

This CVE describes an authorization bypass vulnerability in Tuleap's file release system. Attackers can access file release information in projects th...

Dec 8, 2025
CVE-2025-61148
6.5

An Insecure Direct Object Reference (IDOR) vulnerability in EduplusCampus 3.0.1 allows authenticated users to access other students' personal and fina...

Dec 4, 2025
CVE-2025-41086
6.5

This vulnerability allows attackers to generate unlimited valid licenses for the GAMS licensing system by exploiting an insecure checksum algorithm. A...

Dec 2, 2025

About CWE-639 (CWE-639)

Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.

External reference: View CWE-639 on MITRE CWE →

Monitor CWE-639 Vulnerabilities

Get alerted when new CWE-639 CVEs affect your infrastructure.

Start Monitoring Free