İçeriğe atla
Noroxi

CWE-425 · 211 kayıt

Direct Request ('Forced Browsing')

Bu sınıftaki CVE’ler

211 kayıt

  • Apache OFBiz: Confused controller-view authorization logic (forced browsing)

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    apache · ofbiz4 Eyl 2024

  • Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File

    OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %100

    atlassian · confluence data center2 Ağu 2021

  • CVE-2024-0204
    68Bu hafta

    Authentication Bypass in GoAnywhere MFT

    KritikCVSS 9,8SilahlaştırılmışEPSS %95

    fortra · goanywhere managed file transfer22 Oca 2024

  • CVE-2018-19207
    65Bu hafta

    The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code

    KritikCVSS 9,8SilahlaştırılmışEPSS %88

    van-ons · wp-gdpr-compliance12 Kas 2018

  • CVE-2017-17736
    60Bu hafta

    Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/insta

    KritikCVSS 9,8Kavram kanıtıEPSS %68

    kentico · xperience23 Mar 2018

  • CVE-2019-12583
    49Planlayın

    Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest

    KritikCVSS 9,1Kavram kanıtıEPSS %44

    zyxel · uag2100 firmware27 Haz 2019

  • CVE-2019-16340
    45Planlayın

    Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cg

    KritikCVSS 9,8İstismar yokEPSS %19

    linksys · velop whw0303 firmware21 Kas 2019

  • CVE-2021-40875
    44Planlayın

    Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure.

    YüksekCVSS 7,5Kavram kanıtıEPSS %47

    gurock · testrail22 Eyl 2021

  • CVE-2017-14244
    44Planlayın

    An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directl

    KritikCVSS 9,8Kavram kanıtıEPSS %17

    iball · ib-wra150n firmware17 Eyl 2017

  • CVE-2021-36745
    42Planlayın

    A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers

    KritikCVSS 9,8İstismar yokEPSS %9

    trendmicro · serverprotect29 Eyl 2021

  • CVE-2018-3774
    41Planlayın

    Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Aut

    KritikCVSS 10,0İstismar yokEPSS %4

    url-parse project · url-parse12 Ağu 2018

  • CVE-2021-46378
    40Planlayın

    DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration downlo

    YüksekCVSS 7,5Kavram kanıtıEPSS %32

    dlink · dir-850l firmware4 Mar 2022

  • CVE-2022-28799
    40Planlayın

    The TikTok application before 23.7.3 for Android allows account takeover.

    YüksekCVSS 8,8İstismar yokEPSS %16

    tiktok · tiktok2 Haz 2022

  • CVE-2020-24203
    40Planlayın

    Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management

    KritikCVSS 9,8İstismar yokEPSS %4

    projectworlds · travel management system27 Ağu 2020

  • CVE-2019-7736
    40Planlayın

    D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page.

    KritikCVSS 9,8İstismar yokEPSS %3

    dlink · dir-600m firmware11 Şub 2019

  • CVE-2019-9584
    40Planlayın

    eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details,

    KritikCVSS 9,8İstismar yokEPSS %3

    eq-3 · homematic ccu2 firmware14 Ağu 2019

  • CVE-2018-18922
    40Planlayın

    add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.

    KritikCVSS 9,8İstismar yokEPSS %2

    abisoftgt · ticketly13 Ara 2018

  • CVE-2020-24660
    40Planlayın

    An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used.

    KritikCVSS 9,8İstismar yokEPSS %2

    lemonldap-ng · lemonldap\14 Eyl 2020

  • CVE-2019-12768
    40Planlayın

    An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix.

    KritikCVSS 9,8İstismar yokEPSS %2

    dlink · dap-1650 firmware30 Ara 2020

  • CVE-2019-9552
    40Planlayın

    Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.

    KritikCVSS 9,8İstismar yokEPSS %2

    eloan project · eloan4 Mar 2019

  • CVE-2022-26279
    40Planlayın

    EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

    KritikCVSS 9,8İstismar yokEPSS %2

    eyoucms · eyoucms24 Mar 2022

  • CVE-2018-6624
    39İzleyin

    OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific scree

    KritikCVSS 9,8İstismar yokEPSS %2

    omron · ns series firmware5 Şub 2018

  • CVE-2021-36560
    39İzleyin

    Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of

    KritikCVSS 9,8İstismar yokEPSS %2

    phone shop sales management system project · phone shop sales management system2 Kas 2021

  • CVE-2025-26689
    39İzleyin

    Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions.

    KritikCVSS 9,8İstismar yokEPSS %1

    inaba denki sangyo co., ltd. · choco tei watcher mini (ib-mct001)31 Mar 2025

  • CVE-2024-24592
    39İzleyin

    Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily

    KritikCVSS 9,8İstismar yokEPSS %1

    clear · clearml6 Şub 2024

Tüm zafiyet sınıfları