The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
235 vulnerabilities with CWE-425
CVE-2026-21760
MEDIUM
HCLSoftware DevOps Loop - Unauthorized Access to Admin Functionality via Forced Browsing
CVSS 4.6
CVE-2026-13533
MEDIUM
agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
CVSS 5.3
CVE-2026-10521
HIGH
MB connect line mbCONNECT24 - Authenticated Unintended Access to Critical Program Parameters
CVSS 7.2
CVE-2026-9610
LOW
IBM Datacap and Navigator - Forced Browsing Access Control Bypass
CVSS 2.3
CVE-2026-34028
MEDIUM
Unauthenticated direct access to web data in Wertheim SafeController Software exposes files
CVE-2026-11986
MEDIUM
Red Hat Keycloak admin-ui-ext - Authorization Bypass in Bulk Role Mapping Deletion
CVSS 4.9
CVE-2026-8205
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendar
CVSS 5.3
CVE-2026-42297
HIGH
Argo Workflows Is Missing Authorization in Sync ConfigMap Provider
CVSS 8.3
CVE-2026-7500
MEDIUM
Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled
CVSS 5.4
CVE-2026-35029
HIGH
LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint
CVSS 8.8
CVE-2026-29909
MEDIUM
MRCMS 3.1.2 - Unauthenticated Directory Enumeration via File Management Module
CVSS 5.3
CVE-2026-4900
MEDIUM
code-projects Online Food Ordering System localhost.sql privilege escalation
CVSS 5.3
CVE-2026-34056
HIGH
OpenEMR <=8.0.0.3 Ensora eRx Logs - Privilege Escalation
CVSS 7.7
CVE-2026-34051
MEDIUM
OpenEMR has Improper ACL On Import/Export Popup
CVSS 5.4
CVE-2026-33217
HIGH
NATS allows MQTT clients to bypass ACL checks
CVSS 7.1
CVE-2026-4532
MEDIUM
code-projects Simple Food Ordering System Database Backup food.sql file access
CVSS 5.3
CVE-2026-22732
CRITICAL
Under Some Conditions Spring Security HTTP Headers Are not Written
CVSS 9.1
CVE-2026-32867
MEDIUM
OPEXUS eComplaint unauthenticated file upload
CVSS 5.4
CVE-2026-25679
HIGH
Go standard library net/url < 1.25.8 and 1.26.0 - Direct Request via Invalid URL Host Parsing
CVSS 7.5
CVE-2026-1978
MEDIUM
kalyan02 NanoCMS <0.4 - Info Disclosure
CVSS 5.3
CVE-2026-0790
HIGH
ALGO 8180 IP Audio Alerter Firmware - Unauthenticated Information Disclosure via Direct Request
CVSS 7.5
CVE-2026-0650
CRITICAL
OpenFlagr <= 1.1.18 - Unauthenticated Authentication Bypass via Path Normalization
CVE-2025-15381
HIGH
Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow
CVSS 7.1
CVE-2025-15587
HIGH
Credentials exposure in tinycontrol devices
CVE-2025-52024
CRITICAL
Aptsys POS Platform Web Services < 2025-05-28 - Unauthenticated API Exposure via Internal Testing Tools
CVSS 9.4
Details
Vulnerabilities
235