CWE-425

Direct Request ('Forced Browsing')

Parent: CWE-862 - Missing Authorization

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

235 vulnerabilities with CWE-425
CVE-2022-42197 MEDIUM
Simple Exam Reviewer Management System <1.0 - Privilege Escalation
CVSS 6.5
CVE-2022-42238 HIGH
Merchandise Online Store 1.0 - Vertical Privilege Escalation via Direct Request
CVSS 8.8
CVE-2022-41746 CRITICAL
Trend Micro Apex One - Privilege Escalation
CVSS 9.1
CVE-2022-36158 HIGH
Contec FXA3200 <1.13.00 - Command Injection
CVSS 8.0
CVE-2022-2551 HIGH
Duplicator <1.4.7 - Info Disclosure
CVSS 7.5
CVE-2022-2544 HIGH
Ninja Job Board <1.3.3 - Path Traversal
CVSS 7.5
CVE-2022-34574 MEDIUM
Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 - Info Disclo...
CVSS 5.7
CVE-2022-34573 MEDIUM
Wavlink WiFi-Repeater - Info Disclosure
CVSS 6.3
CVE-2022-34572 MEDIUM
Wavlink WiFi-Repeater - Info Disclosure
CVSS 5.7
CVE-2022-34571 HIGH
Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 - Code Injection
CVSS 8.0
CVE-2022-34570 HIGH
WAVLINK WN579 X3 M79X3.V5030.191012 - Information Disclosure via messages.txt Page
CVSS 7.5
CVE-2022-1551 MEDIUM
SP Project & Document Manager <4.58 - Info Disclosure
CVSS 6.5
CVE-2022-2192 HIGH
HYPR Server <6.15.1 - Privilege Escalation
CVSS 7.5
CVE-2022-29238 MEDIUM
Jupyter Notebook <6.4.12 - Info Disclosure
CVSS 4.3
CVE-2022-31847 HIGH
WAVLINK WN579 X3 M79X3.V5030.180719 - Info Disclosure
CVSS 7.5
CVE-2022-31485 MEDIUM
HID Mercury LP1501/LP1502/LP2500/LP4502/EP4502 <1.29 Unauthenticated Home Page Notes Update
CVSS 5.3
CVE-2022-31484 HIGH
HID Mercury Intelligent Controllers <1.29 - DoS
CVSS 7.5
CVE-2022-31480 HIGH
HID Mercury Intelligent Controllers <1.302-1.296 - DoS
CVSS 7.5
CVE-2022-28799 HIGH
TikTok <23.7.3 - Privilege Escalation
CVSS 8.8
CVE-2022-28991 HIGH
Multi Store Inventory Management System v1.0 - Info Disclosure
CVSS 7.5
CVE-2022-26777 MEDIUM
Zoho ManageEngine Remote Access Plus <10.1.2137.15 - Info Disclosure
CVSS 5.3
CVE-2022-26653 MEDIUM
Zoho ManageEngine Remote Access Plus <10.1.2137.15 - Info Disclosure
CVSS 5.3
CVE-2022-27480 HIGH
SICAM A8000 CP-8031 and CP-8050 Firmware < 4.80 - Unauthenticated Arbitrary File Download
CVSS 7.5
CVE-2022-28365 MEDIUM
Reprise License Manager 14.2 - Info Disclosure
CVSS 5.3
CVE-2022-1077 MEDIUM
TEM FLEX-1080 and FLEX-1085 1.6.0 - Unauthenticated Sensitive Information Exposure via Log Handler
CVSS 5.3
Details
Vulnerabilities 235