← Back
CWE-425

240 CVEs • Abstraction: Base

Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

JSON object

Loading...

CVEs (240)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wavlink
1Wn579x3 Firmware
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.
1Thinkcmf
1Thinkcmf
Jun 17, 2026
Jun 14, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the backg...Show more
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.Show less
1Money Transfer Management System Project
1Money Transfer Management System
Jun 17, 2026
Jun 10, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.
2Carrier
Hidglobal
14Ep4502 Firmware
Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 more
Jun 17, 2026
Jun 6, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP150...Show more
An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29.Show less
2Carrier
Hidglobal
14Ep4502 Firmware
Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 more
Jun 17, 2026
Jun 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP...Show more
An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The impact of this vulnerability is that an unauthenticated attacker could restrict access to the web interface to legitimate users and potentially requiring them to use the default user dip switch procedure to gain access back.Show less
2Carrier
Hidglobal
14Ep4502 Firmware
Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 more
Jun 17, 2026
Jun 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1...Show more
An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The attacker needs to have a properly signed and encrypted binary, loading the firmware to the device ultimately triggers a reboot.Show less
1Tiktok
1Tiktok
Jun 17, 2026
Jun 2, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to le...Show more
The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached JavaScript interface for the takeover with one click.Show less
1Bdtask
1Multi Store Inventory Management System
Jun 17, 2026
May 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.
1Bender
2Cc612 Firmware
Icc15xx Firmware
Jun 17, 2026
Apr 27, 2022
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Apr 16, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Apr 16, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
1Siemens
2Sicam A8000 Cp 8031 Firmware
Sicam A8000 Cp 8050 Firmware
Jun 17, 2026
Apr 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This cou...Show more
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This could allow unauthenticated attackers to download these files.Show less
1Reprisesoftware
1Reprise License Manager
Jun 17, 2026
Apr 9, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, pr...Show more
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.Show less
1Tem
2Flex 1080 Firmware
Flex 1085 Firmware
Jun 17, 2026
Mar 29, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log Handler. A direct request leads to information disclosure of hardware i...Show more
A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log Handler. A direct request leads to information disclosure of hardware information. The attack can be initiated remotely and does not require any form of authentication.Show less
1Eyoucms
1Eyoucms
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
1Smartertools
1Smartertrack
Jun 17, 2026
Mar 14, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
1Dlink
1Dir 850l Firmware
Jun 17, 2026
Mar 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.
1Ametys
1Ametys
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languag...Show more
The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords.Show less
2Debian
Twistedmatrix
2Debian Linux
Treq
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such co...Show more
treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such cookies are not bound to a single domain, and are therefore sent to *every* domain ("supercookies"). This can potentially cause sensitive information to leak upon an HTTP redirect to a different domain., e.g. should `https://example.com` redirect to `http://cloudstorageprovider.com` the latter will receive the cookie `session`. Treq 2021.1.0 and later bind cookies given to request methods (`treq.request`, `treq.get`, `HTTPClient.request`, `HTTPClient.get`, etc.) to the origin of the *url* parameter. Users are advised to upgrade. For users unable to upgrade Instead of passing a dictionary as the *cookies* argument, pass a `http.cookiejar.CookieJar` instance with properly domain- and scheme-scoped cookies in it.Show less
1Ray Ban
4Stories Rw4002 601/71 50 22 Firmware
Stories Rw4003 65582v 48 23 FirmwareStories Rw4005 656013 51 20 Firmware+1 more
Jun 17, 2026
Jan 14, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107...Show more
A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107460.6810.0.Show less