The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
223 vulnerabilities with CWE-425
CVE-2026-7500
MEDIUM
Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled
CVSS 5.4
CVE-2026-29909
MEDIUM
MRCMS 3.1.2 - Path Traversal
CVSS 5.3
CVE-2026-4900
MEDIUM
code-projects Online Food Ordering System localhost.sql privilege escalation
CVSS 5.3
CVE-2026-34056
HIGH
OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data
CVSS 7.7
CVE-2026-34051
MEDIUM
OpenEMR has Improper ACL On Import/Export Popup
CVSS 5.4
CVE-2026-4532
MEDIUM
code-projects Simple Food Ordering System Database Backup food.sql file access
CVSS 5.3
CVE-2026-22732
CRITICAL
Under Some Conditions Spring Security HTTP Headers Are not Written
CVSS 9.1
CVE-2026-32867
MEDIUM
OPEXUS eComplaint unauthenticated file upload
CVSS 5.4
CVE-2026-25679
HIGH
url.Parse - Auth Bypass
CVSS 7.5
CVE-2026-1978
MEDIUM
kalyan02 NanoCMS <0.4 - Info Disclosure
CVSS 5.3
CVE-2026-0790
HIGH
Algosolutions 8180 IP Audio Alerter Firmware - Information Disclosure
CVSS 7.5
CVE-2026-0650
CRITICAL
Flagr - Missing Authentication
CVE-2025-15587
HIGH
Credentials exposure in tinycontrol devices
CVE-2025-52024
CRITICAL
Aptsys Gemscms Backend < 2025-05-28 - Missing Authorization
CVSS 9.4
CVE-2025-15153
LOW
PbootCMS <3.2.12 - Info Disclosure
CVSS 3.7
CVE-2025-67844
MEDIUM
Mintlify Platform <2025-11-15 - Info Disclosure
CVSS 5.0
CVE-2025-65011
HIGH
WODESYS WD- R608U - Info Disclosure
CVE-2025-26381
MEDIUM
Unknown - Info Disclosure
CVE-2025-14697
LOW
Shenzhen Sixun Software Sixun Shanghui Group Business Management Sy...
CVSS 3.7
CVE-2025-57823
LOW
Fortinet FortiAuthenticator <6.6.7 - Info Disclosure
CVSS 2.7
CVE-2025-6195
MEDIUM
GitLab EE <18.4.5-18.6.1 - Info Disclosure
CVSS 4.3
CVE-2025-62778
MEDIUM
Frappe Learning <2.39.1 - Info Disclosure
CVSS 5.3
CVE-2025-11280
LOW
Frappe LMS 2.35.0 - Direct Request in Assignment Picture Handler
CVSS 3.7
CVE-2025-59797
MEDIUM
Profession Fit 5.0.99 Build 44910 - Auth Bypass
CVSS 5.8
CVE-2025-10287
LOW
roncoo-pay <9428382af21cd5568319eae7429b7e1d0332ff40 - Unknown Vuln
CVSS 3.1
Details
Vulnerabilities
223