The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
226 vulnerabilities with CWE-425
CVE-2026-34028
MEDIUM
Unauthenticated direct access to web data in Wertheim SafeController Software exposes files
CVE-2026-11986
MEDIUM
Red Hat Keycloak admin-ui-ext - Authorization Bypass in Bulk Role Mapping Deletion
CVSS 4.9
CVE-2026-8205
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendar
CVSS 5.3
CVE-2026-7500
MEDIUM
Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled
CVSS 5.4
CVE-2026-29909
MEDIUM
MRCMS 3.1.2 - Unauthenticated Directory Enumeration via File Management Module
CVSS 5.3
CVE-2026-4900
MEDIUM
code-projects Online Food Ordering System localhost.sql privilege escalation
CVSS 5.3
CVE-2026-34056
HIGH
OpenEMR <=8.0.0.3 Ensora eRx Logs - Privilege Escalation
CVSS 7.7
CVE-2026-34051
MEDIUM
OpenEMR has Improper ACL On Import/Export Popup
CVSS 5.4
CVE-2026-4532
MEDIUM
code-projects Simple Food Ordering System Database Backup food.sql file access
CVSS 5.3
CVE-2026-22732
CRITICAL
Under Some Conditions Spring Security HTTP Headers Are not Written
CVSS 9.1
CVE-2026-32867
MEDIUM
OPEXUS eComplaint unauthenticated file upload
CVSS 5.4
CVE-2026-25679
HIGH
Go standard library net/url < 1.25.8 and 1.26.0 - Direct Request via Invalid URL Host Parsing
CVSS 7.5
CVE-2026-1978
MEDIUM
kalyan02 NanoCMS <0.4 - Info Disclosure
CVSS 5.3
CVE-2026-0790
HIGH
ALGO 8180 IP Audio Alerter Firmware - Unauthenticated Information Disclosure via Direct Request
CVSS 7.5
CVE-2026-0650
CRITICAL
OpenFlagr <= 1.1.18 - Unauthenticated Authentication Bypass via Path Normalization
CVE-2025-15587
HIGH
Credentials exposure in tinycontrol devices
CVE-2025-52024
CRITICAL
Aptsys POS Platform Web Services < 2025-05-28 - Unauthenticated API Exposure via Internal Testing Tools
CVSS 9.4
CVE-2025-15153
LOW
pbootcms < 3.2.12 - Direct Request Access to SQLite Database File
CVSS 3.7
CVE-2025-67844
MEDIUM
Mintlify Platform <2025-11-15 - Info Disclosure
CVSS 5.0
CVE-2025-65011
HIGH
WODESYS WD- R608U - Info Disclosure
CVE-2025-26381
MEDIUM
Johnson Controls OpenBlue Workplace < 2025.1.2 - Unauthorized Information Access via Forced Browsing
CVE-2025-14697
LOW
Shenzhen Sixun Software Sixun Shanghui Group Business Management Sy...
CVSS 3.7
CVE-2025-57823
LOW
Fortinet FortiAuthenticator <6.6.7 - Info Disclosure
CVSS 2.7
CVE-2025-6195
MEDIUM
GitLab EE <18.4.5-18.6.1 - Info Disclosure
CVSS 4.3
CVE-2025-62778
MEDIUM
Frappe Learning <2.39.1 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
226