CWE-425— Direct Request ('Forced Browsing')
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.— MITRE CWE catalog
249 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-425page 1 of 5
- CVE-2020-10181CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-11
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.
- CVE-2024-45195CRITICALCVSS 7.5EG 9.0⚠ KEV2024-09-04
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
- CVE-2021-26085CRITICALCVSS 5.3EG 9.0⚠ KEV2021-08-03
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from v…
- CVE-2018-3774CRITICALCVSS 10.0EG 10.02018-08-12
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
- CVE-2026-32867CRITICALCVSS 9.8EG 9.82026-03-19
OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPub.aspx'. Users would see these unexpected files in cases. U…
- CVE-2022-43110CRITICALCVSS 9.8EG 9.82025-08-22
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system in…
- CVE-2025-26689CRITICALCVSS 9.8EG 9.82025-03-31
Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product…
- CVE-2024-24592CRITICALCVSS 9.8EG 9.82024-02-06
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.
- CVE-2024-0204CRITICALCVSS 9.8EG 9.82024-01-22
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
- CVE-2022-45276CRITICALCVSS 9.8EG 9.82022-11-23
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.
- CVE-2022-26279CRITICALCVSS 9.8EG 9.82022-03-24
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
- CVE-2021-36560CRITICALCVSS 9.8EG 9.82021-11-02
Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.
- CVE-2021-36745CRITICALCVSS 9.8EG 9.82021-09-29
A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to …
- CVE-2021-24215CRITICALCVSS 9.8EG 9.82021-04-12
An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Uncontrolled access to the website customization functionality and global CMS settings, like /wp-admin/customization.php …
- CVE-2019-12768CRITICALCVSS 9.8EG 9.82020-12-30
An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass authentication via forceful browsing.
- CVE-2020-24660CRITICALCVSS 9.8EG 9.82020-09-14
An issue was discovered in LemonLDAP::NG through 2.0.8, when NGINX is used. An attacker may bypass URL-based access control to protected Virtual Hosts by submitting a non-normalized URI. This also affects versions before 0.5.2 of the "Lemo…
- CVE-2020-24203CRITICALCVSS 9.8EG 9.82020-08-27
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.
- CVE-2019-16340CRITICALCVSS 9.8EG 9.82019-11-21
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.
- CVE-2019-9584CRITICALCVSS 9.8EG 9.82019-08-14
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration. This is related to impr…
- CVE-2019-9884CRITICALCVSS 9.8EG 9.82019-07-25
eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.
- CVE-2019-9552CRITICALCVSS 9.8EG 9.82019-03-04
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.
- CVE-2019-7736CRITICALCVSS 9.8EG 9.82019-02-11
D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may overlap CVE-2019-13101.
- CVE-2018-18922CRITICALCVSS 9.8EG 9.82018-12-13
add_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.
- CVE-2018-19207CRITICALCVSS 9.8EG 9.82018-11-12
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.
- CVE-2017-17736CRITICALCVSS 9.8EG 9.82018-03-23
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.
- CVE-2018-6624CRITICALCVSS 9.8EG 9.82018-02-05
OMRON NS devices 1.1 through 1.3 allow remote attackers to bypass authentication via a direct request to the .html file for a specific screen, as demonstrated by monitor.html.
- CVE-2017-14244CRITICALCVSS 9.8EG 9.82017-09-17
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by …
- CVE-2023-1699CRITICALCVSS 4.3EG 9.82023-03-30
Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in versi…
- CVE-2020-35391CRITICALCVSS 9.6EG 9.62021-01-01
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vuln…
- CVE-2025-52024CRITICALCVSS 9.4EG 9.42026-01-23
A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated users. By accessing specific URLs, an attacker is presented with a directory-style index lis…
- CVE-2026-0650CRITICALCVSS 9.3EG 9.32026-01-07
OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and a…
- CVE-2025-1542CRITICALCVSS 9.3EG 9.32025-03-26
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects …
- CVE-2026-22732CRITICALCVSS 9.1EG 9.12026-03-19
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written. This issue affects Spring Security Servlet applications using lazy (defa…
- CVE-2025-6352CRITICALCVSS 9.1EG 9.12025-06-20
A vulnerability classified as problematic has been found in code-projects Automated Voting System 1.0. Affected is an unknown function of the file /vote.php of the component Backend. The manipulation leads to direct request. It is possible…
- CVE-2024-33897CRITICALCVSS 9.1EG 9.12024-08-06
A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.
- CVE-2022-41746CRITICALCVSS 9.1EG 9.12022-10-10
A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first ob…
- CVE-2019-12583CRITICALCVSS 9.1EG 9.12019-06-27
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access…
- CVE-2017-10833CRITICALCVSS 9.1EG 9.12017-08-29
"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to bypass access restriction to view information or modify configurations via unspecified vectors.
- CVE-2002-1798CRITICALCVSS 9.1EG 9.12002-12-31
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.
- CVE-2026-80275HIGHCVSS 8.8EG 8.82026-10-01
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to ove…
- CVE-2026-35029HIGHCVSS 8.8EG 8.82026-04-06
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then us…
- CVE-2023-5786HIGHCVSS 8.8EG 8.82023-10-26
A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be…
- CVE-2022-42238HIGHCVSS 8.8EG 8.82022-10-11
A Vertical Privilege Escalation issue in Merchandise Online Store v.1.0 allows an attacker to get access to the admin dashboard.
- CVE-2021-44582HIGHCVSS 8.8EG 8.82022-06-10
A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.
- CVE-2022-28799HIGHCVSS 8.8EG 8.82022-06-02
The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force the com.zhiliaoapp.musically WebView to load an arbitrary website. This may allow an attacker to leverage an attached …
- CVE-2020-11561HIGHCVSS 8.8EG 8.82020-04-07
In NCH Express Invoice 7.25, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as the "Add New Item" screen.
- CVE-2019-11326HIGHCVSS 8.8EG 8.82019-09-20
An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product is protected by a login. A guest is allowed to login. Once logged in as a guest, an attacker can browse a URL …
- CVE-2019-14347HIGHCVSS 8.8EG 8.82019-08-06
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.
- CVE-2018-18862HIGHCVSS 8.8EG 8.82019-03-21
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+Sys…
- CVE-2018-19109HIGHCVSS 8.8EG 8.82018-11-08
tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edit a column.
Map vulnerabilities like CWE-425 to your infrastructure
EchelonGraph correlates every CVE — across CWE-425 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →