CWE-425

Direct Request ('Forced Browsing')

Parent: CWE-862 - Missing Authorization

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

235 vulnerabilities with CWE-425
CVE-2020-35391 CRITICAL
Tenda N300 F3 12.01.01.48 - Info Disclosure
CVSS 9.6
CVE-2020-13474 MEDIUM
NCH Express Accounts <8.24 - Privilege Escalation
CVSS 6.5
CVE-2020-7541 MEDIUM
Schneider Electric Modicon M340 - Unauthenticated Sensitive Data Exposure
CVSS 5.3
CVE-2020-29656 HIGH
RT-AC88U Download Master <3.1.0.108 - Info Disclosure
CVSS 7.5
CVE-2020-28937 HIGH
OpenClinic 0.8.2 - Unauthenticated Protected Health Information Exposure via /tests/ URI
CVSS 7.5
CVE-2020-24765 HIGH
InterMind iMind Server <3.13.65 - Info Disclosure
CVSS 7.5
CVE-2020-26150 HIGH
Logaritmo Aware CallManager 2012 - Info Disclosure
CVSS 7.5
CVE-2020-24660 CRITICAL
LemonLDAP::NG < 2.0.8 - Unauthenticated URL Access Control Bypass via Non-Normalized URI
CVSS 9.8
CVE-2020-24203 CRITICAL
Projects World Travel Management System v1.0 - RCE
CVSS 9.8
CVE-2020-13850 HIGH
Artica Pandora FMS 7.44 - Info Disclosure
CVSS 7.5
CVE-2020-11561 HIGH
NCH Express Invoice 7.25 - Privilege Escalation
CVSS 8.8
CVE-2020-10248 HIGH
BWA DiREX-Pro <1.2181 - Info Disclosure
CVSS 7.5
CVE-2020-8439 MEDIUM
Monstra CMS <3.0.4 - Privilege Escalation
CVSS 6.5
CVE-2019-20484 HIGH
Viki Vera <4.9.1.26180 - Info Disclosure
CVSS 8.1
CVE-2019-25012 HIGH
Webform Report <7.x-1.x-dev - Info Disclosure
CVSS 7.5
CVE-2019-12768 CRITICAL
D-Link DAP-1650 <1.04B02_J65H - Auth Bypass
CVSS 9.8
CVE-2019-2388 MEDIUM
MongoDB Ops Manager <4.0.9-4.1.5 - Info Disclosure
CVSS 5.8
CVE-2019-17646 HIGH
Centreon <19.10.2 - Info Disclosure
CVSS 7.5
CVE-2019-17645 HIGH
Centreon <2.8.31, 18.10.9, 19.04.6, 19.10.3 - Info Disclosure
CVSS 7.5
CVE-2019-17644 HIGH
Centreon <2.8-30, 18.10-8, 19.04-5, 19.10-2 - Info Disclosure
CVSS 7.5
CVE-2019-17643 HIGH
Centreon <2.8-30,18.10-8,19.04-5,19.10-2 - Info Disclosure
CVSS 7.5
CVE-2019-16388 MEDIUM
PEGA Platform 8.3.0 - Info Disclosure
CVSS 4.3
CVE-2019-16386 MEDIUM
PEGA Platform 7.x-8.x - Info Disclosure
CVSS 4.3
CVE-2019-16340 CRITICAL
Belkin Linksys Velop <1.1.8.192419 - Info Disclosure
CVSS 9.8
CVE-2019-14927 HIGH
Mitsubishi Electric and INEA ME-RTU Firmware < 2.02 and < 3.0 - Unauthenticated Sensitive Configuration Download
CVSS 7.5
Details
Vulnerabilities 235