The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
235 vulnerabilities with CWE-425
CVE-2020-35391
CRITICAL
Tenda N300 F3 12.01.01.48 - Info Disclosure
CVSS 9.6
CVE-2020-13474
MEDIUM
NCH Express Accounts <8.24 - Privilege Escalation
CVSS 6.5
CVE-2020-7541
MEDIUM
Schneider Electric Modicon M340 - Unauthenticated Sensitive Data Exposure
CVSS 5.3
CVE-2020-29656
HIGH
RT-AC88U Download Master <3.1.0.108 - Info Disclosure
CVSS 7.5
CVE-2020-28937
HIGH
OpenClinic 0.8.2 - Unauthenticated Protected Health Information Exposure via /tests/ URI
CVSS 7.5
CVE-2020-24765
HIGH
InterMind iMind Server <3.13.65 - Info Disclosure
CVSS 7.5
CVE-2020-26150
HIGH
Logaritmo Aware CallManager 2012 - Info Disclosure
CVSS 7.5
CVE-2020-24660
CRITICAL
LemonLDAP::NG < 2.0.8 - Unauthenticated URL Access Control Bypass via Non-Normalized URI
CVSS 9.8
CVE-2020-24203
CRITICAL
Projects World Travel Management System v1.0 - RCE
CVSS 9.8
CVE-2020-13850
HIGH
Artica Pandora FMS 7.44 - Info Disclosure
CVSS 7.5
CVE-2020-11561
HIGH
NCH Express Invoice 7.25 - Privilege Escalation
CVSS 8.8
CVE-2020-10248
HIGH
BWA DiREX-Pro <1.2181 - Info Disclosure
CVSS 7.5
CVE-2020-8439
MEDIUM
Monstra CMS <3.0.4 - Privilege Escalation
CVSS 6.5
CVE-2019-20484
HIGH
Viki Vera <4.9.1.26180 - Info Disclosure
CVSS 8.1
CVE-2019-25012
HIGH
Webform Report <7.x-1.x-dev - Info Disclosure
CVSS 7.5
CVE-2019-12768
CRITICAL
D-Link DAP-1650 <1.04B02_J65H - Auth Bypass
CVSS 9.8
CVE-2019-2388
MEDIUM
MongoDB Ops Manager <4.0.9-4.1.5 - Info Disclosure
CVSS 5.8
CVE-2019-17646
HIGH
Centreon <19.10.2 - Info Disclosure
CVSS 7.5
CVE-2019-17645
HIGH
Centreon <2.8.31, 18.10.9, 19.04.6, 19.10.3 - Info Disclosure
CVSS 7.5
CVE-2019-17644
HIGH
Centreon <2.8-30, 18.10-8, 19.04-5, 19.10-2 - Info Disclosure
CVSS 7.5
CVE-2019-17643
HIGH
Centreon <2.8-30,18.10-8,19.04-5,19.10-2 - Info Disclosure
CVSS 7.5
CVE-2019-16388
MEDIUM
PEGA Platform 8.3.0 - Info Disclosure
CVSS 4.3
CVE-2019-16386
MEDIUM
PEGA Platform 7.x-8.x - Info Disclosure
CVSS 4.3
CVE-2019-16340
CRITICAL
Belkin Linksys Velop <1.1.8.192419 - Info Disclosure
CVSS 9.8
CVE-2019-14927
HIGH
Mitsubishi Electric and INEA ME-RTU Firmware < 2.02 and < 3.0 - Unauthenticated Sensitive Configuration Download
CVSS 7.5
Details
Vulnerabilities
235