CWE-425

Direct Request ('Forced Browsing')

Parent: CWE-862 - Missing Authorization

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

235 vulnerabilities with CWE-425
CVE-2025-32367 HIGH
Oz Forensics <4.0.8 - Info Disclosure
CVSS 8.6
CVE-2025-26689 CRITICAL
CHOCO TEI WATCHER mini - Info Disclosure
CVSS 9.8
CVE-2025-1542 CRITICAL
OXARI ServiceDesk <2.0.324.0 - Privilege Escalation
CVE-2025-2147 MEDIUM
Beijing Zhide Intelligent Internet Technology Modern Farm Digital I...
CVSS 5.3
CVE-2024-23573 LOW
Hclsoftware Aftermarket Epc - Direct Request ('Forced Browsing')
CVSS 3.7
CVE-2024-58343 MEDIUM
Vision Helpdesk <5.7.0 - Deserialization
CVSS 4.3
CVE-2024-55075 MEDIUM
grocy < 4.3.0 - Unauthenticated Sensitive Information Exposure via Direct Request
CVSS 4.3
CVE-2024-9945 MEDIUM
Fortra's GoAnywhere MFT <7.7.0 - Info Disclosure
CVSS 5.3
CVE-2024-11049 LOW
ZKTeco ZKBio Time 9.0.1 - Direct Request in Image File Handler
CVSS 3.7
CVE-2024-45195 HIGH KEV
Apache OFBiz <18.12.16 - Info Disclosure
CVSS 7.5
CVE-2024-7753 MEDIUM
SourceCodester Clinics Patient Management System 1.0 - Info Disclosure
CVSS 5.3
CVE-2024-42001 HIGH
Vonets Industrial WiFi Bridge Firmware < 3.3.23.6.9 - Unauthenticated Authentication Bypass via Direct Request
CVSS 8.6
CVE-2024-33897 CRITICAL
HMS Networks ewon Cosy+ Firmware >=21.0s0 <21.2s10 - Availability Issue via Certificate Signing Request
CVSS 9.1
CVE-2024-7153 MEDIUM
Netgear WN604 <20240719 - Direct Request
CVSS 5.3
CVE-2024-7080 MEDIUM
Insurance Management System 1.0 - Path Traversal in /E-Insurance/
CVSS 5.3
CVE-2024-39868 HIGH
SINEMA Remote Connect Server <V3.2 SP1 - Auth Bypass
CVSS 7.6
CVE-2024-39867 HIGH
SINEMA Remote Connect Server <V3.2 SP1 - Info Disclosure
CVSS 7.6
CVE-2024-6414 MEDIUM
Parsec Automation TrakSYS 11.x.x - Info Disclosure
CVSS 5.3
CVE-2024-6188 MEDIUM
Parsec Automation TrackSYS 11.x.x - Info Disclosure
CVSS 5.3
CVE-2024-2730 MEDIUM
Mautic < 4.4.9 - Unauthenticated Sensitive Data Exposure via Predictable Landing Page Indices
CVSS 5.3
CVE-2024-0861 MEDIUM
GitLab EE <16.7.6-16.9.1 - Privilege Escalation
CVSS 4.3
CVE-2024-24592 CRITICAL
Allegro AI's ClearML - Info Disclosure
CVSS 9.8
CVE-2024-0456 MEDIUM
GitLab 14.0-16.6.5, 16.7.0-16.7.3, 16.8.0 - Unauthenticated Authorization Bypass via Merge Request Assignment
CVSS 4.3
CVE-2024-0204 CRITICAL
Fortra GoAnywhere MFT Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2023-45598 MEDIUM
AiLux imx6 <imx6_1.0.7-2 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 235