CWE-425
240 CVEs • Abstraction: Base
Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
CVEs (240)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request. |
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the backg...Show more |
1Money Transfer Management System Project 1Money Transfer Management System Jun 17, 2026 Jun 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL. |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP150...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP...Show more |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1...Show more |
The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to le...Show more |
1Bdtask 1Multi Store Inventory Management System Jun 17, 2026 May 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files. |
1Bender 2Cc612 Firmware Icc15xx FirmwareJun 17, 2026 Apr 27, 2022 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot . |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Apr 16, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details. |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Apr 16, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator). |
1Siemens 2Sicam A8000 Cp 8031 Firmware Sicam A8000 Cp 8050 FirmwareJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP-8050 (All versions < V4.80). Affected devices do not require an user to be authenticated to access certain files. This cou...Show more |
1Reprisesoftware 1Reprise License Manager Jun 17, 2026 Apr 9, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, pr...Show more |
1Tem 2Flex 1080 Firmware Flex 1085 FirmwareJun 17, 2026 Mar 29, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability log.cgi of the component Log Handler. A direct request leads to information disclosure of hardware i...Show more |
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata. |
A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010. |
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download. |
The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languag...Show more |
2Debian Twistedmatrix2Debian Linux TreqJun 17, 2026 Feb 1, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such co...Show more |
1Ray Ban 4Stories Rw4002 601/71 50 22 Firmware Stories Rw4003 65582v 48 23 FirmwareStories Rw4005 656013 51 20 Firmware+1 moreJun 17, 2026 Jan 14, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affected versions of device software before 2107...Show more |