The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
235 vulnerabilities with CWE-425
CVE-2022-26279
CRITICAL
EyouCMS v1.5.5 - Unauthenticated Direct Request in /data/sqldata
CVSS 9.8
CVE-2022-24385
MEDIUM
SmarterTrack 100.0.8019.14010 - Info Disclosure
CVSS 6.5
CVE-2022-26159
MEDIUM
Ametys CMS <4.5.0 - Info Disclosure
CVSS 5.3
CVE-2022-23607
MEDIUM
treq 21.1.0-22.1.0 - Exposure of Sensitive Information via Supercookies
CVSS 6.5
CVE-2021-40616
MEDIUM
thinkcmf <5.1.7 - Privilege Escalation
CVSS 6.5
CVE-2021-44582
HIGH
Sourcecodester Money Transfer Management System 1.0 - Privilege Escalation via Forced Browsing
CVSS 8.8
CVE-2021-34588
HIGH
Bender CC612 and ICC15xx Firmware 5.11.0-5.11.1 - Unauthenticated Sensitive Data Exposure via Backup Export
CVSS 8.6
CVE-2021-46378
HIGH
DLink DIR850 ET850-1.08TRb03 - Info Disclosure
CVSS 7.5
CVE-2021-24046
MEDIUM
Ray-Ban Stories <2107460.6810.0 - Info Disclosure
CVSS 5.3
CVE-2021-42748
MEDIUM
Beaver Builder <2.5.0.3 - Auth Bypass
CVSS 5.3
CVE-2021-24831
HIGH
Tab WordPress <1.3.2 - Info Disclosure
CVSS 7.5
CVE-2021-24695
HIGH
Simple Download Monitor <3.9.6 - Info Disclosure
CVSS 7.5
CVE-2021-42671
HIGH
Sourcecodester Engineers Online Portal - Auth Bypass
CVSS 7.5
CVE-2021-36560
CRITICAL
Phone Shop Sales Managements System <1.0 - Auth Bypass
CVSS 9.8
CVE-2021-36745
CRITICAL
Trend Micro ServerProtect - Auth Bypass
CVSS 9.8
CVE-2021-40875
HIGH
Gurock TestRail <7.2.0.3014 - Info Disclosure
CVSS 7.5
CVE-2021-26085
MEDIUM
KEV
Atlassian Confluence Server <7.4.10, >7.5.0-7.12.2 - Info Disclosure
CVSS 5.3
CVE-2021-20114
HIGH
TCExam <= 14.8.1 - Unauthenticated Sensitive Information Exposure via Cache Backup Directory
CVSS 7.5
CVE-2021-28150
MEDIUM
Hongdian H8922 3.0.5 - Information Disclosure
CVSS 5.5
CVE-2021-24238
MEDIUM
Findeo and Realteo < 1.3.1 and < 1.2.4 - Authenticated Arbitrary Property Deletion via property_id Parameter
CVSS 6.5
CVE-2021-24215
CRITICAL
Controlled Admin Access < 1.5.2 - Unauthenticated Improper Access Control
CVSS 9.8
CVE-2021-30144
MEDIUM
GLPI Dashboard <1.0.2 - Auth Bypass
CVSS 4.3
CVE-2021-22180
MEDIUM
GitLab 13.4-13.6.7 - Unauthenticated Direct Request Access to Analytic Pages
CVSS 4.3
CVE-2021-3113
HIGH
Netsia SEBA+ <0.16.1 build 70-e669dcd7 - Info Disclosure
CVSS 7.5
CVE-2020-35570
MEDIUM
MymbCONNECT24 <2.11.2 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
235