CWE-425
235 CVEs • Abstraction: Base
Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
CVEs (235)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1...Show more |
The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to le...Show more |
1Bdtask 1Multi Store Inventory Management System Jun 17, 2026 May 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files. |
1Bender 2Cc612 Firmware Icc15xx FirmwareJun 17, 2026 Apr 27, 2022 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot . |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Apr 16, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details. |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Apr 16, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator). |
1Siemens 2Sicam A8000 Cp 8031 Firmware Sicam A8000 Cp 8050 FirmwareJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This cou...Show more |
1Reprisesoftware 1Reprise License Manager Jun 17, 2026 Apr 9, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, pr...Show more |
1Tem 2Flex 1080 Firmware Flex 1085 FirmwareJun 17, 2026 Mar 29, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log Handler. A direct request leads to information disclosure of hardware i...Show more |
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata. |
A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010. |
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download. |
The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languag...Show more |
2Debian Twistedmatrix2Debian Linux TreqJun 17, 2026 Feb 1, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such co...Show more |
1Ray Ban 4Stories Rw4002 601/71 50 22 Firmware Stories Rw4003 65582v 48 23 FirmwareStories Rw4005 656013 51 20 Firmware+1 moreJun 17, 2026 Jan 14, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107...Show more |
1Fastlinemedia 1Beaver Builder Jun 17, 2026 Jan 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Beaver Builder through 2.5.0.3, attackers can bypass the visibility controls protection mechanism via the REST API. |
All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete ar...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Jun 17, 2026 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the log...Show more |
1Engineers Online Portal Project 1Engineers Online Portal Jun 17, 2026 Nov 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access contro...Show more |
1Phone Shop Sales Management System Project 1Phone Shop Sales Management System Jun 17, 2026 Nov 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin. |