CWE-425 · 211 записей
Direct Request ('Forced Browsing')
CVE этого класса
211 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2024-45195Готовый эксплойт | Apache OFBiz: Confused controller-view authorization logic (forced browsing)apache · ofbiz · CWE-425 | Высокая7,5 | KEV | 100,0 % | 4 сент. 2024 г. |
81Срочно | CVE-2021-26085Готовый эксплойт | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File atlassian · confluence data center · CWE-425 | Средняя5,3 | KEV | 99,9 % | 2 авг. 2021 г. |
68На этой неделе | CVE-2024-0204Готовый эксплойт | Authentication Bypass in GoAnywhere MFTfortra · goanywhere managed file transfer · CWE-425 | Критическая9,8 | — | 95,1 % | 22 янв. 2024 г. |
65На этой неделе | CVE-2018-19207Готовый эксплойт | The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code van-ons · wp-gdpr-compliance · CWE-425 | Критическая9,8 | — | 88,1 % | 12 нояб. 2018 г. |
60На этой неделе | CVE-2017-17736Proof of concept | Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/instakentico · xperience · CWE-425 | Критическая9,8 | — | 68,5 % | 23 мар. 2018 г. |
49В плане | CVE-2019-12583Proof of concept | Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guestzyxel · uag2100 firmware · CWE-425 | Критическая9,1 | — | 43,9 % | 27 июн. 2019 г. |
45В плане | CVE-2019-16340Эксплойта нет | Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cglinksys · velop whw0303 firmware · CWE-425 | Критическая9,8 | — | 19,3 % | 21 нояб. 2019 г. |
44В плане | CVE-2021-40875Proof of concept | Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure.gurock · testrail · CWE-425 | Высокая7,5 | — | 47,5 % | 22 сент. 2021 г. |
44В плане | CVE-2017-14244Proof of concept | An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directliball · ib-wra150n firmware · CWE-425 | Критическая9,8 | — | 17,1 % | 17 сент. 2017 г. |
42В плане | CVE-2021-36745Эксплойта нет | A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers trendmicro · serverprotect · CWE-425 | Критическая9,8 | — | 9,4 % | 29 сент. 2021 г. |
41В плане | CVE-2018-3774Эксплойта нет | Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Auturl-parse project · url-parse · CWE-425 | Критическая10,0 | — | 3,8 % | 12 авг. 2018 г. |
40В плане | CVE-2021-46378Proof of concept | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration downlodlink · dir-850l firmware · CWE-425 | Высокая7,5 | — | 31,9 % | 4 мар. 2022 г. |
40В плане | CVE-2022-28799Эксплойта нет | The TikTok application before 23.7.3 for Android allows account takeover.tiktok · tiktok · CWE-425 | Высокая8,8 | — | 16,0 % | 2 июн. 2022 г. |
40В плане | CVE-2020-24203Эксплойта нет | Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management projectworlds · travel management system · CWE-425 | Критическая9,8 | — | 3,7 % | 27 авг. 2020 г. |
40В плане | CVE-2019-7736Эксплойта нет | D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page.dlink · dir-600m firmware · CWE-425 | Критическая9,8 | — | 2,7 % | 11 февр. 2019 г. |
40В плане | CVE-2019-9584Эксплойта нет | eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details,eq-3 · homematic ccu2 firmware · CWE-425 | Критическая9,8 | — | 2,7 % | 14 авг. 2019 г. |
40В плане | CVE-2018-18922Эксплойта нет | add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.abisoftgt · ticketly · CWE-425 | Критическая9,8 | — | 2,4 % | 13 дек. 2018 г. |
40В плане | CVE-2020-24660Эксплойта нет | An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used.lemonldap-ng · lemonldap\ · CWE-425 | Критическая9,8 | — | 2,4 % | 14 сент. 2020 г. |
40В плане | CVE-2019-12768Эксплойта нет | An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix.dlink · dap-1650 firmware · CWE-425 | Критическая9,8 | — | 2,3 % | 30 дек. 2020 г. |
40В плане | CVE-2019-9552Эксплойта нет | Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.eloan project · eloan · CWE-425 | Критическая9,8 | — | 2,0 % | 4 мар. 2019 г. |
40В плане | CVE-2022-26279Эксплойта нет | EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.eyoucms · eyoucms · CWE-425 | Критическая9,8 | — | 1,8 % | 24 мар. 2022 г. |
39Наблюдать | CVE-2018-6624Эксплойта нет | OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screeomron · ns series firmware · CWE-425 | Критическая9,8 | — | 1,6 % | 5 февр. 2018 г. |
39Наблюдать | CVE-2021-36560Эксплойта нет | Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover ofphone shop sales management system project · phone shop sales management system · CWE-425 | Критическая9,8 | — | 1,5 % | 2 нояб. 2021 г. |
39Наблюдать | CVE-2025-26689Эксплойта нет | Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions.inaba denki sangyo co., ltd. · choco tei watcher mini (ib-mct001) · CWE-425 | Критическая9,8 | — | 1,1 % | 31 мар. 2025 г. |
39Наблюдать | CVE-2024-24592Эксплойта нет | Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily clear · clearml · CWE-425 | Критическая9,8 | — | 1,0 % | 6 февр. 2024 г. |
- CVE-2024-4519590Срочно
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %apache · ofbiz4 сент. 2024 г.
- CVE-2021-2608581Срочно
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center2 авг. 2021 г.
- CVE-2024-020468На этой неделе
Authentication Bypass in GoAnywhere MFT
КритическаяCVSS 9,8Готовый эксплойтEPSS 95 %fortra · goanywhere managed file transfer22 янв. 2024 г.
- CVE-2018-1920765На этой неделе
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code
КритическаяCVSS 9,8Готовый эксплойтEPSS 88 %van-ons · wp-gdpr-compliance12 нояб. 2018 г.
- CVE-2017-1773660На этой неделе
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/insta
КритическаяCVSS 9,8Proof of conceptEPSS 68 %kentico · xperience23 мар. 2018 г.
- CVE-2019-1258349В плане
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest
КритическаяCVSS 9,1Proof of conceptEPSS 44 %zyxel · uag2100 firmware27 июн. 2019 г.
- CVE-2019-1634045В плане
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cg
КритическаяCVSS 9,8Эксплойта нетEPSS 19 %linksys · velop whw0303 firmware21 нояб. 2019 г.
- CVE-2021-4087544В плане
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure.
ВысокаяCVSS 7,5Proof of conceptEPSS 47 %gurock · testrail22 сент. 2021 г.
- CVE-2017-1424444В плане
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directl
КритическаяCVSS 9,8Proof of conceptEPSS 17 %iball · ib-wra150n firmware17 сент. 2017 г.
- CVE-2021-3674542В плане
A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %trendmicro · serverprotect29 сент. 2021 г.
- CVE-2018-377441В плане
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Aut
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %url-parse project · url-parse12 авг. 2018 г.
- CVE-2021-4637840В плане
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration downlo
ВысокаяCVSS 7,5Proof of conceptEPSS 32 %dlink · dir-850l firmware4 мар. 2022 г.
- CVE-2022-2879940В плане
The TikTok application before 23.7.3 for Android allows account takeover.
ВысокаяCVSS 8,8Эксплойта нетEPSS 16 %tiktok · tiktok2 июн. 2022 г.
- CVE-2020-2420340В плане
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %projectworlds · travel management system27 авг. 2020 г.
- CVE-2019-773640В плане
D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %dlink · dir-600m firmware11 февр. 2019 г.
- CVE-2019-958440В плане
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details,
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %eq-3 · homematic ccu2 firmware14 авг. 2019 г.
- CVE-2018-1892240В плане
add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %abisoftgt · ticketly13 дек. 2018 г.
- CVE-2020-2466040В плане
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lemonldap-ng · lemonldap\14 сент. 2020 г.
- CVE-2019-1276840В плане
An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %dlink · dap-1650 firmware30 дек. 2020 г.
- CVE-2019-955240В плане
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eloan project · eloan4 мар. 2019 г.
- CVE-2022-2627940В плане
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eyoucms · eyoucms24 мар. 2022 г.
- CVE-2018-662439Наблюдать
OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific scree
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %omron · ns series firmware5 февр. 2018 г.
- CVE-2021-3656039Наблюдать
Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phone shop sales management system project · phone shop sales management system2 нояб. 2021 г.
- CVE-2025-2668939Наблюдать
Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %inaba denki sangyo co., ltd. · choco tei watcher mini (ib-mct001)31 мар. 2025 г.
- CVE-2024-2459239Наблюдать
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %clear · clearml6 февр. 2024 г.