CWE-425

Direct Request ('Forced Browsing')

Parent: CWE-862 - Missing Authorization

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

223 vulnerabilities with CWE-425
CVE-2022-2192 HIGH
HYPR Server <6.15.1 - Privilege Escalation
CVSS 7.5
CVE-2022-29238 MEDIUM
Jupyter Notebook <6.4.12 - Info Disclosure
CVSS 4.3
CVE-2022-31847 HIGH
WAVLINK WN579 X3 M79X3.V5030.180719 - Info Disclosure
CVSS 7.5
CVE-2022-31485 MEDIUM
HID Mercury - Unauthenticated SSRF
CVSS 5.3
CVE-2022-31484 HIGH
HID Mercury Intelligent Controllers <1.29 - DoS
CVSS 7.5
CVE-2022-31480 HIGH
HID Mercury Intelligent Controllers <1.302-1.296 - DoS
CVSS 7.5
CVE-2022-28799 HIGH
TikTok <23.7.3 - Privilege Escalation
CVSS 8.8
CVE-2022-28991 HIGH
Multi Store Inventory Management System v1.0 - Info Disclosure
CVSS 7.5
CVE-2022-26777 MEDIUM
Zoho ManageEngine Remote Access Plus <10.1.2137.15 - Info Disclosure
CVSS 5.3
CVE-2022-26653 MEDIUM
Zoho ManageEngine Remote Access Plus <10.1.2137.15 - Info Disclosure
CVSS 5.3
CVE-2022-27480 HIGH
Siemens Sicam A8000 Cp-8031 Firmware < 4.80 - Missing Authorization
CVSS 7.5
CVE-2022-28365 MEDIUM
Reprise License Manager 14.2 - Info Disclosure
CVSS 5.3
CVE-2022-1077 MEDIUM
TEM Flex-1085 Firmware - Information Disclosure
CVSS 5.3
CVE-2022-26279 CRITICAL
EyouCMS v1.5.5 - Info Disclosure
CVSS 9.8
CVE-2022-24385 MEDIUM
SmarterTrack 100.0.8019.14010 - Info Disclosure
CVSS 6.5
CVE-2022-26159 MEDIUM
Ametys CMS <4.5.0 - Info Disclosure
CVSS 5.3
CVE-2022-23607 MEDIUM
Twistedmatrix Treq < 22.1.0 - Information Disclosure
CVSS 6.5
CVE-2021-40616 MEDIUM
thinkcmf <5.1.7 - Privilege Escalation
CVSS 6.5
CVE-2021-44582 HIGH
Money Transfer Management System - Privilege Escalation
CVSS 8.8
CVE-2021-34588 HIGH
Bender/ebee - Info Disclosure
CVSS 8.6
CVE-2021-46378 HIGH
DLink DIR850 ET850-1.08TRb03 - Info Disclosure
CVSS 7.5
CVE-2021-24046 MEDIUM
Ray-Ban Stories <2107460.6810.0 - Info Disclosure
CVSS 5.3
CVE-2021-42748 MEDIUM
Beaver Builder <2.5.0.3 - Auth Bypass
CVSS 5.3
CVE-2021-24831 HIGH
Tab WordPress <1.3.2 - Info Disclosure
CVSS 7.5
CVE-2021-24695 HIGH
Simple Download Monitor <3.9.6 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 223