CWE-425
240 CVEs • Abstraction: Base
Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
CVEs (240)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fastlinemedia 1Beaver Builder Jun 17, 2026 Jan 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Beaver Builder through 2.5.0.3, attackers can bypass the visibility controls protection mechanism via the REST API. |
All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete ar...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Jun 17, 2026 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the log...Show more |
1Engineers Online Portal Project 1Engineers Online Portal Jun 17, 2026 Nov 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access contro...Show more |
1Phone Shop Sales Management System Project 1Phone Shop Sales Management System Jun 17, 2026 Nov 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin. |
1Mitsubishielectric 1Smartrtu Firmware Nov 21, 2024 Oct 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI. |
A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a...Show more |
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a Gurock TestRail application, disclosing a...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Aug 3, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version...Show more |
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files. |
Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backup2.cgi. |
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any authenticated users to delete arbitrary pr...Show more |
1Wpruby 1Controlled Admin Access Jun 17, 2026 Apr 12, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin...Show more |
The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For examp...Show more |
An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unauthorized users to access details on analytic pages. |
2Helmholz Mbconnectline4Mbconnect24 Mymbconnect24Myrex24+1 moreJun 17, 2026 Feb 16, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via fo...Show more |
Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admi...Show more |
An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser after logging in. |
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14...Show more |
1Webform Report Project 1Webform Report Jun 17, 2026 Jan 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page. NOTE: This project is not covered by Drupal's security advisory policy. |