CWE-425

Direct Request ('Forced Browsing')

Parent: CWE-862 - Missing Authorization

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

235 vulnerabilities with CWE-425
CVE-2019-17503 MEDIUM
Kirona DRS 5.5.3.5 - Info Disclosure
CVSS 5.3
CVE-2019-11326 HIGH
Topcon Positioning Net-G5 GNSS Receiver <5.2.2 - Info Disclosure
CVSS 8.8
CVE-2019-1220 MEDIUM
Internet Explorer - Security Feature Bypass via URL Security Zone Validation
CVSS 4.3
CVE-2019-9584 CRITICAL
eQ-3 Homematic AddOn 'CloudMatic' - Privilege Escalation
CVSS 9.8
CVE-2019-13030 HIGH
eQ-3 Homematic CCU3 - Info Disclosure
CVSS 8.2
CVE-2019-14347 HIGH
Schben Adive < 2.0.7 - Privilege Escalation via User Addition
CVSS 8.8
CVE-2019-9884 CRITICAL
eClass platform < ip.2.5.10.2.1 - Auth Bypass
CVSS 9.8
CVE-2019-13981 MEDIUM
Directus 7 API <2.3.0 - Info Disclosure
CVSS 5.3
CVE-2019-12583 CRITICAL
Zyxel UAG/USG/ZyWall Firmware - Unauthenticated Guest Account Generation via Free Time Component
CVSS 9.1
CVE-2019-1899 MEDIUM
Cisco RV110W/RV130W/RV215W - Info Disclosure
CVSS 5.3
CVE-2019-1898 MEDIUM
Cisco RV110W, RV130W, and RV215W - Info Disclosure
CVSS 5.3
CVE-2019-3934 MEDIUM
Crestron AM-100 and AM-101 - Unauthenticated Improper Access Control via login.cgi
CVSS 5.3
CVE-2019-3933 MEDIUM
Crestron AM-100 and AM-101 - Unauthenticated Access Control Bypass via /images/browserslide.jpg
CVSS 5.3
CVE-2019-3916 HIGH
Verizon Fios Quantum Gateway G1100 Firmware 02.01.00.05 - Unauthenticated Information Disclosure via API Endpoint
CVSS 7.5
CVE-2019-3917 HIGH
Nokia I-240W-Q GPON ONT Firmware 3FE54567BOZJ19 - Unauthenticated Telnetd Enablement via HTTP Request
CVSS 7.5
CVE-2019-9552 CRITICAL
eloan 3.0-2018-09-20 - Unauthenticated Directory Listing via Direct Request
CVSS 9.8
CVE-2019-6551 HIGH
Pangea Communications Internet FAX ATA <3.1.8 - Auth Bypass
CVSS 7.5
CVE-2019-7736 CRITICAL
D-Link DIR-600M C1 3.04 - Auth Bypass
CVSS 9.8
CVE-2019-6126 HIGH
PHP Scripts Mall Advance Peer to Peer MLM Script <1.7.0 - Auth Bypass
CVSS 7.5
CVE-2018-16060 HIGH
Mitsubishi Electric Europe B.V. SmartRTU - Info Disclosure
CVSS 7.5
CVE-2018-18862 HIGH
BMC Remedy Mid-Tier 7.1.00-9.1.02.003 - Privilege Escalation
CVSS 8.8
CVE-2018-6669 MEDIUM
McAfee Application Control/Change Control <7.0.1 - RCE
CVSS 6.3
CVE-2018-18922 CRITICAL
AbiSoft Ticketly 1.0 - Unauthenticated Privilege Escalation via add_user Action
CVSS 9.8
CVE-2018-19620 MEDIUM
showdoc < 2.4.2 - Unauthenticated Incorrect Access Control via Modified page_id
CVSS 4.3
CVE-2018-19207 CRITICAL
Van Ons WP GDPR Compliance <1.4.3 - RCE
CVSS 9.8
Details
Vulnerabilities 235