← Back
CWE-425

235 CVEs • Abstraction: Base

Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

JSON object

Loading...

CVEs (235)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dogukanurker
1Flaskblog
Jun 17, 2026
Aug 19, 2025
9.3 CRITICAL· v4
6.5 MEDIUM· v3
N/A· v2
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adm...Show more
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.Show less
1Irohasoft
1Iroha Board
Jun 17, 2026
Jun 26, 2025
5.3 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can log in to the affected product.
-
-
Jun 17, 2026
Jun 24, 2025
N/A· v4
4.2 MEDIUM· v3
N/A· v2
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit iss...Show more
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not treated as a secret and might be mentioned publicly, or it could be predicted).Show less
-
-
Jun 17, 2026
Jun 23, 2025
N/A· v4
6.4 MEDIUM· v3
N/A· v2
Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclos...Show more
Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within the frontend shop. Anyone can create a customer account and easily exploit these. Successful exploitation results in disclosure of the PII of other customers and the deletion of their reviews of products on the website. To be specific, an attacker could view the order details of any order by browsing to /en/account/orders/_ORDER_ID_ or use the address and billing information of other customers by manipulating the shipping_address_id and billing_address_id parameters when making an order (this information is then reflected in the receipt). Additionally, an attacker could delete the reviews of other users by sending a DELETE request to /en/account/reviews/_REVIEW_ID.Show less
1Fabian
1Automated Voting System
Jun 17, 2026
Jun 20, 2025
5.5 MEDIUM· v4
9.1 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability classified as problematic has been found in code-projects Automated Voting System 1.0. Affected is an unknown function of the file /vote.php of the component Backend. The manipulation leads to direct requ...Show more
A vulnerability classified as problematic has been found in code-projects Automated Voting System 1.0. Affected is an unknown function of the file /vote.php of the component Backend. The manipulation leads to direct request. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less
-
-
Jun 17, 2026
May 21, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.
-
-
Jun 17, 2026
May 21, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
-
-
Jun 17, 2026
May 21, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference.
-
-
Jun 17, 2026
May 21, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
1Snipeitapp
1Snipe It
Jun 17, 2026
May 2, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
1Ververica
1Ververica Platform
Jun 17, 2026
Apr 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request.
-
-
Jun 17, 2026
Apr 24, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.
-
-
Jun 17, 2026
Apr 23, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.
-
-
Jun 17, 2026
Apr 11, 2025
N/A· v4
8.6 HIGH· v3
N/A· v2
The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure Direct Object Reference. NOTE: the number 4.0.8 was used for both the unpatched and patched versions.
-
-
Jun 17, 2026
Mar 31, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted,...Show more
Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be altered.Show less
-
-
Jun 17, 2026
Mar 26, 2025
9.3 CRITICAL· v4
N/A· v3
N/A· v2
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This...Show more
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.Show less
1Caishixiong
1Modern Farm Digital Integrated Management System
Jun 17, 2026
Mar 10, 2025
6.9 MEDIUM· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation le...Show more
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Grocy Project
1Grocy
Jun 17, 2026
Jan 6, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.
-
-
Jun 17, 2026
Dec 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows external access to the resources in certain admin root folders.
1Zkteco
1Zkbio Time
Jun 17, 2026
Nov 10, 2024
6.3 MEDIUM· v4
3.7 LOW· v3
2.6 LOW· v2
A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component Image File Handler. The manipulation leads to direct re...Show more
A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component Image File Handler. The manipulation leads to direct request. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less