CWE-425 · 211 kayıt
Direct Request ('Forced Browsing')
Bu sınıftaki CVE’ler
211 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2024-45195Silahlaştırılmış | Apache OFBiz: Confused controller-view authorization logic (forced browsing)apache · ofbiz · CWE-425 | Yüksek7,5 | KEV | %100,0 | 4 Eyl 2024 |
81Hemen | CVE-2021-26085Silahlaştırılmış | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File atlassian · confluence data center · CWE-425 | Orta5,3 | KEV | %99,9 | 2 Ağu 2021 |
68Bu hafta | CVE-2024-0204Silahlaştırılmış | Authentication Bypass in GoAnywhere MFTfortra · goanywhere managed file transfer · CWE-425 | Kritik9,8 | — | %95,1 | 22 Oca 2024 |
65Bu hafta | CVE-2018-19207Silahlaştırılmış | The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code van-ons · wp-gdpr-compliance · CWE-425 | Kritik9,8 | — | %88,1 | 12 Kas 2018 |
60Bu hafta | CVE-2017-17736Kavram kanıtı | Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/instakentico · xperience · CWE-425 | Kritik9,8 | — | %68,5 | 23 Mar 2018 |
49Planlayın | CVE-2019-12583Kavram kanıtı | Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guestzyxel · uag2100 firmware · CWE-425 | Kritik9,1 | — | %43,9 | 27 Haz 2019 |
45Planlayın | CVE-2019-16340İstismar yok | Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cglinksys · velop whw0303 firmware · CWE-425 | Kritik9,8 | — | %19,3 | 21 Kas 2019 |
44Planlayın | CVE-2021-40875Kavram kanıtı | Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure.gurock · testrail · CWE-425 | Yüksek7,5 | — | %47,5 | 22 Eyl 2021 |
44Planlayın | CVE-2017-14244Kavram kanıtı | An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directliball · ib-wra150n firmware · CWE-425 | Kritik9,8 | — | %17,1 | 17 Eyl 2017 |
42Planlayın | CVE-2021-36745İstismar yok | A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers trendmicro · serverprotect · CWE-425 | Kritik9,8 | — | %9,4 | 29 Eyl 2021 |
41Planlayın | CVE-2018-3774İstismar yok | Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Auturl-parse project · url-parse · CWE-425 | Kritik10,0 | — | %3,8 | 12 Ağu 2018 |
40Planlayın | CVE-2021-46378Kavram kanıtı | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration downlodlink · dir-850l firmware · CWE-425 | Yüksek7,5 | — | %31,9 | 4 Mar 2022 |
40Planlayın | CVE-2022-28799İstismar yok | The TikTok application before 23.7.3 for Android allows account takeover.tiktok · tiktok · CWE-425 | Yüksek8,8 | — | %16,0 | 2 Haz 2022 |
40Planlayın | CVE-2020-24203İstismar yok | Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management projectworlds · travel management system · CWE-425 | Kritik9,8 | — | %3,7 | 27 Ağu 2020 |
40Planlayın | CVE-2019-7736İstismar yok | D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page.dlink · dir-600m firmware · CWE-425 | Kritik9,8 | — | %2,7 | 11 Şub 2019 |
40Planlayın | CVE-2019-9584İstismar yok | eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details,eq-3 · homematic ccu2 firmware · CWE-425 | Kritik9,8 | — | %2,7 | 14 Ağu 2019 |
40Planlayın | CVE-2018-18922İstismar yok | add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.abisoftgt · ticketly · CWE-425 | Kritik9,8 | — | %2,4 | 13 Ara 2018 |
40Planlayın | CVE-2020-24660İstismar yok | An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used.lemonldap-ng · lemonldap\ · CWE-425 | Kritik9,8 | — | %2,4 | 14 Eyl 2020 |
40Planlayın | CVE-2019-12768İstismar yok | An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix.dlink · dap-1650 firmware · CWE-425 | Kritik9,8 | — | %2,3 | 30 Ara 2020 |
40Planlayın | CVE-2019-9552İstismar yok | Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.eloan project · eloan · CWE-425 | Kritik9,8 | — | %2,0 | 4 Mar 2019 |
40Planlayın | CVE-2022-26279İstismar yok | EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.eyoucms · eyoucms · CWE-425 | Kritik9,8 | — | %1,8 | 24 Mar 2022 |
39İzleyin | CVE-2018-6624İstismar yok | OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screeomron · ns series firmware · CWE-425 | Kritik9,8 | — | %1,6 | 5 Şub 2018 |
39İzleyin | CVE-2021-36560İstismar yok | Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover ofphone shop sales management system project · phone shop sales management system · CWE-425 | Kritik9,8 | — | %1,5 | 2 Kas 2021 |
39İzleyin | CVE-2025-26689İstismar yok | Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions.inaba denki sangyo co., ltd. · choco tei watcher mini (ib-mct001) · CWE-425 | Kritik9,8 | — | %1,1 | 31 Mar 2025 |
39İzleyin | CVE-2024-24592İstismar yok | Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily clear · clearml · CWE-425 | Kritik9,8 | — | %1,0 | 6 Şub 2024 |
- CVE-2024-4519590Hemen
Apache OFBiz: Confused controller-view authorization logic (forced browsing)
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100apache · ofbiz4 Eyl 2024
- CVE-2021-2608581Hemen
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %100atlassian · confluence data center2 Ağu 2021
- CVE-2024-020468Bu hafta
Authentication Bypass in GoAnywhere MFT
KritikCVSS 9,8SilahlaştırılmışEPSS %95fortra · goanywhere managed file transfer22 Oca 2024
- CVE-2018-1920765Bu hafta
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code
KritikCVSS 9,8SilahlaştırılmışEPSS %88van-ons · wp-gdpr-compliance12 Kas 2018
- CVE-2017-1773660Bu hafta
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/insta
KritikCVSS 9,8Kavram kanıtıEPSS %68kentico · xperience23 Mar 2018
- CVE-2019-1258349Planlayın
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest
KritikCVSS 9,1Kavram kanıtıEPSS %44zyxel · uag2100 firmware27 Haz 2019
- CVE-2019-1634045Planlayın
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cg
KritikCVSS 9,8İstismar yokEPSS %19linksys · velop whw0303 firmware21 Kas 2019
- CVE-2021-4087544Planlayın
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure.
YüksekCVSS 7,5Kavram kanıtıEPSS %47gurock · testrail22 Eyl 2021
- CVE-2017-1424444Planlayın
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directl
KritikCVSS 9,8Kavram kanıtıEPSS %17iball · ib-wra150n firmware17 Eyl 2017
- CVE-2021-3674542Planlayın
A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers
KritikCVSS 9,8İstismar yokEPSS %9trendmicro · serverprotect29 Eyl 2021
- CVE-2018-377441Planlayın
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Aut
KritikCVSS 10,0İstismar yokEPSS %4url-parse project · url-parse12 Ağu 2018
- CVE-2021-4637840Planlayın
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration downlo
YüksekCVSS 7,5Kavram kanıtıEPSS %32dlink · dir-850l firmware4 Mar 2022
- CVE-2022-2879940Planlayın
The TikTok application before 23.7.3 for Android allows account takeover.
YüksekCVSS 8,8İstismar yokEPSS %16tiktok · tiktok2 Haz 2022
- CVE-2020-2420340Planlayın
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management
KritikCVSS 9,8İstismar yokEPSS %4projectworlds · travel management system27 Ağu 2020
- CVE-2019-773640Planlayın
D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page.
KritikCVSS 9,8İstismar yokEPSS %3dlink · dir-600m firmware11 Şub 2019
- CVE-2019-958440Planlayın
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details,
KritikCVSS 9,8İstismar yokEPSS %3eq-3 · homematic ccu2 firmware14 Ağu 2019
- CVE-2018-1892240Planlayın
add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.
KritikCVSS 9,8İstismar yokEPSS %2abisoftgt · ticketly13 Ara 2018
- CVE-2020-2466040Planlayın
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used.
KritikCVSS 9,8İstismar yokEPSS %2lemonldap-ng · lemonldap\14 Eyl 2020
- CVE-2019-1276840Planlayın
An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix.
KritikCVSS 9,8İstismar yokEPSS %2dlink · dap-1650 firmware30 Ara 2020
- CVE-2019-955240Planlayın
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
KritikCVSS 9,8İstismar yokEPSS %2eloan project · eloan4 Mar 2019
- CVE-2022-2627940Planlayın
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
KritikCVSS 9,8İstismar yokEPSS %2eyoucms · eyoucms24 Mar 2022
- CVE-2018-662439İzleyin
OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific scree
KritikCVSS 9,8İstismar yokEPSS %2omron · ns series firmware5 Şub 2018
- CVE-2021-3656039İzleyin
Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of
KritikCVSS 9,8İstismar yokEPSS %2phone shop sales management system project · phone shop sales management system2 Kas 2021
- CVE-2025-2668939İzleyin
Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions.
KritikCVSS 9,8İstismar yokEPSS %1inaba denki sangyo co., ltd. · choco tei watcher mini (ib-mct001)31 Mar 2025
- CVE-2024-2459239İzleyin
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily
KritikCVSS 9,8İstismar yokEPSS %1clear · clearml6 Şub 2024