CWE-425
235 CVEs • Abstraction: Base
Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
CVEs (235)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Edge Internet ExplorerJun 17, 2026 Sep 11, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'. |
1Eq 3 2Homematic Ccu2 Firmware Homematic Ccu3 FirmwareJun 17, 2026 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This...Show more |
eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to start or stop the Node.js process, resulting in the ability to obtain mediola configuration details. Th...Show more |
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script. |
eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page. |
1Rangerstudio 1Directus 7 Api Jun 17, 2026 Jul 19, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configuration option in which the file collection...Show more |
1Zyxel 14Uag2100 Firmware Uag4100 FirmwareUag5100 Firmware+11 moreJun 17, 2026 Jun 27, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthor...Show more |
1Cisco 3Rv110w Firmware Rv130w FirmwareRv215w FirmwareJun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability i...Show more |
1Cisco 3Rv110w Firmware Rv130w FirmwareRv215w FirmwareJun 17, 2026 Jun 20, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due...Show more |
1Crestron 2Am 100 Firmware Am 101 FirmwareJun 17, 2026 Apr 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sending a crafted HTTP POST request to login.cgi. A remote, unauthenticated attacker can use this vulne...Show more |
1Crestron 2Am 100 Firmware Am 101 FirmwareJun 17, 2026 Apr 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code simply by requesting /images/browserslide.jpg via HTTP. A remote, unauthenticated attacker can use this...Show more |
1Verizon 1Fios Quantum Gateway G1100 Firmware Jun 17, 2026 Apr 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API...Show more |
1Bmc 2Remedy Action Request System Remedy Mid TierNov 21, 2024 Mar 21, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admi...Show more |
1Nokia 1I 240w Q Gpon Ont Firmware Jun 17, 2026 Mar 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router via a crafted HTTP request. |
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI. |
Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, which may be used to cause a continual deni...Show more |
D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may overlap CVE-2019-13101. |
1Advance Peer To Peer Mlm Script Project 1Advance Peer To Peer Mlm Script Jun 17, 2026 Jan 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended access restrictions by directly navigating to admin/dashboard.php or admin/user.php, as demonstrated b...Show more |
1Mcafee 1Application Change Control Jun 17, 2026 Dec 20, 2018 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form. |
add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request. |