The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Volume of CVEs assigned to CWE-425 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
235 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45195HIGH Direct Request ('Forced Browsing') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.16.
Users are recommended to upgrade to version 18.12.16, which fi | Sep 4, 2024 | 7.5 | 97 | YES | YES |
CVE-2021-26085MEDIUM Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. | Aug 3, 2021 | 5.3 | 97 | YES | YES |
CVE-2024-0204CRITICAL Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal. | Jan 22, 2024 | 9.8 | 94 | NO | YES |
CVE-2018-19207CRITICAL The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishan | Nov 12, 2018 | 9.8 | 89 | NO | YES |
CVE-2017-17736CRITICAL Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS A | Mar 23, 2018 | 9.8 | 78 | NO | YES |
CVE-2021-40875HIGH Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the /files.md5 file on the client side of a G | Sep 22, 2021 | 7.5 | 70 | NO | YES |
CVE-2019-17503MEDIUM An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contain | Oct 11, 2019 | 5.3 | 64 | NO | YES |
CVE-2019-12583CRITICAL Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the acco | Jun 27, 2019 | 9.1 | 64 | NO | YES |
CVE-2026-35029HIGH LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user | Apr 6, 2026 | 8.8 | 61 | NO | YES |
CVE-2019-14927HIGH An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnera | Oct 28, 2019 | 7.5 | 56 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.