CWE-425
240 CVEs • Abstraction: Base
Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
CVEs (240)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get database schema information...Show more |
1Linksys 3Velop Whw0301 Firmware Velop Whw0302 FirmwareVelop Whw0303 FirmwareJun 17, 2026 Nov 21, 2019 N/A· v4 9.8 CRITICAL· v3 6.4 MEDIUM· v2 Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI. |
2Inea Mitsubishielectric2Me Rtu Firmware Smartrtu FirmwareJun 17, 2026 Oct 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download th...Show more |
1Kirona 1Dynamic Resource Scheduling Jun 17, 2026 Oct 11, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive information about the databa...Show more |
An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product is protected by a login. A guest is allowed to login. Once logged in as a guest, an attacke...Show more |
1Microsoft 2Edge Internet ExplorerJun 17, 2026 Sep 11, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'. |
1Eq 3 2Homematic Ccu2 Firmware Homematic Ccu3 FirmwareJun 17, 2026 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This...Show more |
eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to start or stop the Node.js process, resulting in the ability to obtain mediola configuration details. Th...Show more |
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script. |
eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page. |
1Rangerstudio 1Directus 7 Api Jun 17, 2026 Jul 19, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configuration option in which the file collection...Show more |
1Zyxel 14Uag2100 Firmware Uag4100 FirmwareUag5100 Firmware+11 moreJun 17, 2026 Jun 27, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthor...Show more |
1Cisco 3Rv110w Firmware Rv130w FirmwareRv215w FirmwareJun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability i...Show more |
1Cisco 3Rv110w Firmware Rv130w FirmwareRv215w FirmwareJun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due...Show more |
1Crestron 2Am 100 Firmware Am 101 FirmwareJun 17, 2026 Apr 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi. A remote, unauthenticated attacker can use this vulne...Show more |
1Crestron 2Am 100 Firmware Am 101 FirmwareJun 17, 2026 Apr 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/browserslide.jpg via HTTP. A remote, unauthenticated attacker can use this...Show more |
1Verizon 1Fios Quantum Gateway G1100 Firmware Jun 17, 2026 Apr 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API...Show more |
1Bmc 2Remedy Action Request System Remedy Mid TierNov 21, 2024 Mar 21, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admi...Show more |
1Nokia 1I 240w Q Gpon Ont Firmware Jun 17, 2026 Mar 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router via a crafted HTTP request. |
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI. |